Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

HTTP basic auth is not secure.


basic auth is secure, if used in combination with TLS.


Unfortunately, that only takes care of one of the vulnerabilities that comes with basic auth.

As basic auth sends the header for every single request, it is also vulnerable to CSRF attacks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: