5 ms·
Urls aren't encrypted. If you're on an entirely secure network, and you don't mind users seeing user name + password in the url then it might not be a problem.
by steverb 13y ago
Urls aren't encrypted.
If you're on an entirely secure network, and you don't mind users seeing user name + password in the url then it might not be a problem.
- feralmoan 13y agoI think the (right) assumption is that http basic auth should always be used with TLS. Its why you can't generally install multiple certs on the same ip without sni support, no http headers, uri, url's etc. make it over the wire before the transport layer handshake. I've never seen these credentials appear in logs, and many browsers strip the auth preamble from the address bar. Anyway just food for thought, http basic isn't as bad as made out.
- voxic11 13y agoUrls are encrypted over TLS