Account creation at


When one creates an account here the email verification contains a link to a HTTP URL rather than a HTTPS one, eg:

Of course this is mitigated by the STS header that is sent so client browsers which have visited the site previously shouldn’t make a unencrypted request.


I have fixed this by turning on the ‘use https’ site setting, which overrides the per-request HTTPS detection to always HTTPS.


