4 ms·
are people really suggesting basic auth again, is it 1993 outside? Basic auth is horrendous security practice, you're passing a header that has your user and pa
by cp9 7y ago
are people really suggesting basic auth again, is it 1993 outside? Basic auth is horrendous security practice, you're passing a header that has your user and password in plaintext, it's insane to suggest that in 2019
- thekyle 7y agoWhat makes submitting a plaintext password in an Auth header worse than submitting a plaintext password in a POST body?
- cp9 7y agothere's no way to log out, the browser has to store it instead of a session cookie which can be invalidated if it's stolen. plus what's in this comment https://security.stackexchange.com/questions/988/is-basic-auth-secure-if-done-over-https#comment209113_17216 https://security.stackexchange.com/questions/988/is-basic-au...
- thekyle 7y agoThanks, I didn't realize that the password was re-sent for every request to the site.