3 ms·
> You wouldn't write your username and passwords on a postcard and mail it for the world to see, so why are you doing it online? Every time you log in to Twitte
by benjoffe 16y ago
> You wouldn't write your username and passwords on a postcard and mail it for the world to see, so why are you doing it online? Every time you log in to Twitter, Facebook or any other service that uses a plain HTTP connection that's essentially what you're doing.
I'll be honest, I didn't read any more of the article after this totally false statement in the intro. Facebook and Twitter both use https for login (they are http pages that submit to a https endpoint that redirect to http, that way https is used for authentication but never appears in the url).
- djjose 16y agoTrue, but it's not obvious to non-techies (hence the article). I was curious how FB did logins when we were creating our API and site since I couldn't fathom them sending l/p's without https. A long look at their source on the homepage is really all it took to guess what they did (a guess, I could still be wrong). After a good deal of painful eyestrain I noticed they seemed to be using their internal APIs via JS over https for authentication. I wonder how many "non-https" sites also do this. I'd still wager a good deal of sites still send authentication over plain ol' http though. Is the lag for authentication purposes really that bad? Anyone have any hard metrics?
- watchandwait 16y agoYeah but even with https login, if a site also serves regular http pages, cookies with session credentials are still visible (on open networks) and the session can be hijacked.
- kinofcain 16y agoSort of. Twitter and Facebook still serve their home pages as HTTP and provide a login form that posts over HTTPS. The problem is that I can do a MITM attack on the unsecured home page and put my own script in there that siphons off the user's password when they click the submit button. So the HTTPS-posting form prevents the eavesdropping case, but not the man-in-the-middle case. That's how the Tunisian government was harvesting their citizen's facebook logins: http://www.thehackernews.com/2011/03/exposure-how-does-tunisian-government.html http://www.thehackernews.com/2011/03/exposure-how-does-tunis...