4 ms·
> http://getmirrorshades.com/view.html?siteKey=[SECRET_SITE_KEY] http://getmirrorshades.com/view.html?siteKey=[SECRET_SITE_KE... someone sniffing the network t
by lettersdigits 10y ago
> http://getmirrorshades.com/view.html?siteKey=[SECRET_SITE_KEY] http://getmirrorshades.com/view.html?siteKey=[SECRET_SITE_KE...
someone sniffing the network traffic can see the SECRET_SITE_KEY ..
isn't it a security concern? or am i missing anything?
- aparks517 10y agoThanks. HTTPS is now live. :)
- bencollier49 10y agoBut you've got the secret site key in your server logs as it's in all the GET statements. Don't use third-party log analysis would be the suggestion I suppose.
- lettersdigits 10y agoi didn't even think about that angle (being careful from third party logs for http GETs with sensitive info in the url). thanks
- lettersdigits 10y agoi think it's not enough: one of the comments of the question here: http://stackoverflow.com/questions/499591/are-https-urls-encrypted http://stackoverflow.com/questions/499591/are-https-urls-enc... says: "It's probably a bad idea to put confidential data in the URL anyway. It will be displayed in the browser's address bad too, remember? People don't like it if their password is visible to anyone who happens to glance at the screen" you can just display a form with an input field for the secret key, which will be HTTP POSTed and only THEN you should display the account's data (while the url doesn't disclose the secret key)