| 
 Posted by David Dorward on 06/16/09 11:28 
Toby Inkster wrote: 
 
> Wherever I redirect my script to is free to be on regular HTTP without 
> compromising the login data, correct? 
 
> Correct, *assuming* you *don't* do anything like: 
 
<snip> 
 
In other words - if the user needs to remain logged in, then whatever you 
use the track them after leaving SSL is vulnerable to being sniffed and 
copied.  
 
So stay in HTTPS for the entire time the user is logged in if you want to 
keep the user's credentials (and the data they send and recieve while 
logged in) secure. 
 
--  
David Dorward       <http://blog.dorward.me.uk/>   <http://dorward.me.uk/> 
                     Home is where the ~/.bashrc is
 
  
Navigation:
[Reply to this message] 
 |