Two more details...
- Yes, forcing the login page into HTTPS is probably possible, but I'm not willing to put work into that (because of the above mostly),
- And among the disadvantages of HTTPS are that it's slower. But AFAIK, HTTP/2.0 should be based off SPDY and has the secure flag enabled by default, so it should be as fast as HTTP/1.1 without the penalties incurred by HTTPS, I think. I'm not sure how SSL certificates will work for HTTP/2 though, since it's a PITA to build them, and dedicated IPs are a real problem on shared hosting, obviously...
:edit: Apparently, if you have no SSL certificate, then you can't use HTTP/2... Simple as that, uh.
Posted: September 24th, 2014, 11:45 AM
It's more complicated than that; apparently, nothing is set in stone regarding HTTP/2, so I'll just wait until something more concrete surfaces...
Anyway, I've just gone to the https version of wedge.org, and posting from it, and I'm happy to report that apparently it's working fine (once of course you get past the browser prompting you to accept the certificate as it's signed for alwaysdata, not for wedge.org).