-
Notifications
You must be signed in to change notification settings - Fork 32
Description
This website authenticates to Github api via HTTP Basic Authentication but all api calls are done over SSL so your password is safe. More on Wikipedia.
Note that your password is only sent to Github and and sent encrypted.
Seeing the issue here? Hint, the site itself is HTTP: http://www.dorukdestan.com/github-label-manager/
The thing with the weakest link and so. Ref: https://blog.mozilla.org/tanvi/2016/01/28/no-more-passwords-over-http-please/
That just shows me that you seem to favor "coolness" (if having an own domain without HTTPS still counts as cool these days) over the absolute minimum of security. This is pretty much the same as in freshshell/fresh#139.
Please don’t let users in the dark about this and please don’t make such bold statements.