Warning: substr() expects parameter 2 to be long, string given in /srv/www/midg3t.net/index.php on line 60
tedp - Taciturn

Warning: Cannot modify header information - headers already sent by (output started at /srv/www/midg3t.net/index.php:60) in /srv/www/midg3t.net/weblog.ted on line 76

Taciturn

All entries (archive)

Transmitting passwords over HTTPS is safe, but serving the login form over HTTP is not. The attack vector is that an active attacker can send a custom login form with a different form submission address, compromising users' passwords.

I noticed this when using the Debian mentors login. Fortunately the login page is also available over HTTPS if you adjust the URI yourself, but ideally it would be the default.

Comments

There are no comments on this entry.

Post comment


Also available in RSS.