Here is the BuzzFeed login form that loads over HTTP
Add some credentials and log in
Let’s see if it the request is over HTTPS?
That’s a big NO. A GET request is made to: http://www.buzzfeed.com/buzfeed/_www_login
Let’s try adding the “s” ourselves. https://www.buzzfeed.com/buzfeed/_www_login
Do they have any TLS or SSL configured at all?
The Akamai configuration supports secure protocols, but on only 1 of 3 servers. The two AWS servers don’t have secure protocols configured.
Test Qualys SSL Labs results for yourself: https://www.ssllabs.com/ssltest/analyze.html?d=buzzfeed.com
Site: BuzzFeed.com
Type: Log in form over http, request to http
Needs protecting: Password
First identified: 11/13/15