Hacker News new | past | comments | ask | show | jobs | submit login

"Also, I don't see a problem with the practice of putting sensitive data in GET variables if the website is protected by SSL - Am I missing something?"

GET requests are logged by the web server and in the browser history in plain text, even for SSL requests.

Therefore any server administrator or computer user can have access to those information just reading the server log or the browser history.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: