-
Notifications
You must be signed in to change notification settings - Fork 17
Site doesnt work with https! #17
Comments
Wouldn't be hard for whoever has control of the domain to add SSL with Let's Encrypt. I can help if needed. |
I take this job; |
@the-wendell |
I'd like to know what are the application level implications for this, since this looks mostly DNS. please correct me if i'm wrong. |
Because the site utilizes a sign up form, the email & password that are being sent over the network are vulnerable to being intercepted by malicious users. The site should encrypt that information before it leaves the local browser to resolve this potential security flaw . Moreover, the site should be immune to the critical session hijacking vulnerability surrounding the remember me feature when logging in. |
No description provided.
The text was updated successfully, but these errors were encountered: