I am working on the deployment of a small community site. To register a user, no more than a username, email address and password are required. I do not even ask for a name and, of course, did not store any confidential data.
Should I still invest in an SSL certificate? Would it be a terrible practice to pass a user password without one?
This is just a personal project, so I would like to avoid additional costs if I could, but I cannot help but feel that I will be irresponsible if I do not defend everything correctly.
source
share