Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
flux293m
on June 4, 2014
|
parent
|
context
|
favorite
| on:
UK government's password checker sends plaintext p...
Even over HTTPS it wouldn't be secure. The password is in the URL so would be stored in the users browser history, and possibly also web-server logs and sent as referrer headers with assets on the secured page.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: