You should never transmit sensitive data without encryption. Being logged in somewhere constitutes transmitting sensitive data.
For Pivotal Tracker:
- Make sure you set "Always Use HTTPS" under "My Profile".
- As you can not rely on every member of a project to have this enabled, you should also tick "Use HTTPS" on the settings page of each project.
Posted by Arne Hartherz to makandra dev (2010-11-19 09:04)