3 ms·
So if you offer a https only API and anyone makes the mistake of using http instead, what should be the response of your system? A simple error message with 404
by barredo 13y ago
So if you offer a https only API and anyone makes the mistake of using http instead, what should be the response of your system? A simple error message with 404 code and without special/identifying headers?
- rb2k_ 13y agoThe main problem isn't the response, the problem is that on the initial request, the insecure password will be sent in plaintext.
- deleted 13y ago[deleted]
- drivebyacct2 13y agoIsn't this sort of issue basically only going to happen during development or such?
- barredo 13y agoBut that's not the problem of the API provider. If you explain that you only allow HTTPS and someone makes an HTTP on an unsecured connection, well...
- smtddr 13y agoOh but it IS the problem with the provider. Or rather, it will be when some crazy PR storm hits the interwebz with "$YOURCOMPANYNAME leaked passwords!" when someone comes up with some clever way to hack/manipulate traffic with XSS or something. I was able to fetch private authtokens of a Wii game because port 80 was open on one of nintendo's servers(I assume it's there to test in plain text and just didn't close it later) and I was able to fool the software into using port 80 instead of port 443. That wouldn't have worked if port 80 was closed.
- barredo 13y agoMakes total sense. Thanks
- burrows 13y agoPretending that your customers won't make mistakes? Sounds insecure.
- h2s 13y agoFrom the article: close port 80 on your API host
- miorel 13y agoThe proper response should be to expire the insecurely-sent passwords.
- Adirael 13y agoClever. I like this much more than just closing the port 80.