3 ms·
I am not a web developer, but I have to ask. Using basic authentication over SSL, does that mean if you entered https://user:pass@domain https://user:pass@doma
by microDude 10y ago
I am not a web developer, but I have to ask.
Using basic authentication over SSL, does that mean if you entered https://user:pass@domain https://user:pass@domain that the user and pass would be sent in the clear, or does this get put into the header and encrypted?
- dincer 10y agoYes, basic authentication is encrypted over SSL but there are more problems to that: https://security.stackexchange.com/questions/988/is-basic-auth-secure-if-done-over-https https://security.stackexchange.com/questions/988/is-basic-au...
- csbowe 10y agoIt's base64 encoded and put into the header, according to the article.
- colejohnson66 10y agoBut if you use HTTPS, those headers are encrypted, right?
- kevin_thibedeau 10y agoThe problem is they can end up in the logs of the receiving server and if that gets hacked...