Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Http basic authentication urls are never secure (that requires https) and are not supported in links by browsers these days.


This bug only affects HTTPS basic auth, given that the issue is with SNI (and, of course, that basic auth over HTTP doesn’t have any encryption to leak around).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: