Skip to content

"password is safe" Seriously? #6

@ypid

Description

@ypid

This website authenticates to Github api via HTTP Basic Authentication but all api calls are done over SSL so your password is safe. More on Wikipedia.
Note that your password is only sent to Github and and sent encrypted.

Seeing the issue here? Hint, the site itself is HTTP: http://www.dorukdestan.com/github-label-manager/
The thing with the weakest link and so. Ref: https://blog.mozilla.org/tanvi/2016/01/28/no-more-passwords-over-http-please/

That just shows me that you seem to favor "coolness" (if having an own domain without HTTPS still counts as cool these days) over the absolute minimum of security. This is pretty much the same as in freshshell/fresh#139.

Please don’t let users in the dark about this and please don’t make such bold statements.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions