TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: How bad is this security hole?

3 pointsby dmcgover 14 years ago
I've just found my username and password in a URL in my web history, after editing my account details with a major UK ISP.<p>Give me some perspective - how bad is this, and how seriously should they be taking it?

2 comments

infinityover 14 years ago
What exactly is happening there if you log into your account? Is it the case that there is no https (instead of http) and the username and password are transmitted as parameters like this:<p>http : // some.example.com/login.php?username=someuser&#38;password=ultrasecret<p>Then your username and password can be captured by any computer between your browser and the website you were trying to log in. This should not be happening anymore today, it is very insecure.
评论 #2125793 未加载
评论 #2125794 未加载
frankwilesover 14 years ago
I'd definitely report it and switch ISPs if it wasn't fixed in short order. Even if it was an account to something I didn't really care all that much about like controlling my DVR.
评论 #2125853 未加载