3 ms·
OK, red alert on a cyber security risk with this site. Your URL is logged, therefore everything you type is readable by anyone farming your URLs. What am I mi
by calrain 2y ago
OK, red alert on a cyber security risk with this site.
Your URL is logged, therefore everything you type is readable by anyone farming your URLs.
What am I missing here, why does this seem like such a security risk.
- jasperry 2y agoThe URL is encrypted in HTTPS/TLS. An eavesdropper can see you making a TCP connection to the server, but everything above that layer, including the HTTP header with the URL, is encrypted payload.
- helsinkiandrew 2y agoNothing after the # will be sent over HTTPs but doesn't use of URL means its lost if you loose the URL - wouldn't local web storage be more 'secure' and also possibly syncable to other devices?
- paulnpace 2y ago> Nothing after the # will be sent over HTTPs I notice it wants to run Cloudflare insights. Do they track this?
- dontdoxxme 2y agoThey do, so in theory everything after the '#' is not sent, however it frequently sends a request to "https://notepadtab.com/cdn-cgi/rum https://notepadtab.com/cdn-cgi/rum?" which is part of Cloudflare Analytics (https://www.cloudflare.com/en-au/web-analytics/ https://www.cloudflare.com/en-au/web-analytics/). The payload includes "timingsV2" data, which leaks the hash part to the server.
- deleted 2y ago[deleted]