TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Tumblr transmits your Gmail/Hotmail/Yahoo password in the clear

6 点作者 kwm将近 15 年前

3 条评论

tptacek将近 15 年前
Re [2], it doesn't matter if a form's action posts to an https link. Using an unencrypted HTML form to post to an encrypted post handler is a security anti-pattern. Attackers will simply intercept the form render instead of the post, alter the form, and insert themselves in the middle of the transaction. This attack is no harder than intercepting the POST itself.<p>Don't <i>ever</i> give your Google Mail password to another company. Even if they "encrypt" it on the wire, you can never be sure they're not storing it insecurely on the back end. Please take this from someone who spends his days beating up other people's applications: everyone screws up something.
评论 #1577643 未加载
评论 #1578851 未加载
kwm将近 15 年前
Thomas: Wholeheartedly agree. Thus, [1].<p>I probably should have made this very clear: While the lack of encryption is maddening, the very worst part is that Tumblr isn't performing this data pull properly (and Google does provide a proper and relatively safe mechanism for doing what they're doing--it's used by Facebook, LinkedIn and anyone else with a need, API key and good conscience).
icarus_drowning将近 15 年前
While I wasn't a huge fan of the tone here ("They really don’t give a shit, huh?"), it does seem like something that needs to be brought to everyone's attention.
评论 #1575642 未加载