TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How bad is this security hole?

3 点作者 dmcg超过 14 年前
I've just found my username and password in a URL in my web history, after editing my account details with a major UK ISP.<p>Give me some perspective - how bad is this, and how seriously should they be taking it?

2 条评论

infinity超过 14 年前
What exactly is happening there if you log into your account? Is it the case that there is no https (instead of http) and the username and password are transmitted as parameters like this:<p>http : // some.example.com/login.php?username=someuser&#38;password=ultrasecret<p>Then your username and password can be captured by any computer between your browser and the website you were trying to log in. This should not be happening anymore today, it is very insecure.
评论 #2125793 未加载
评论 #2125794 未加载
frankwiles超过 14 年前
I'd definitely report it and switch ISPs if it wasn't fixed in short order. Even if it was an account to something I didn't really care all that much about like controlling my DVR.
评论 #2125853 未加载