@sconlan most common practice is indeed to transmit passwords in clear text over https to the server.
then someone enables debug logging on incoming traffic behind the LB after its back in plain text.
@sconlan most common practice is indeed to transmit passwords in clear text over https to the server.
then someone enables debug logging on incoming traffic behind the LB after its back in plain text.
Jonkman Microblog is a social network, courtesy of SOBAC Microcomputer Services. It runs on GNU social, version 1.2.0-beta5, available under the GNU Affero General Public License.
All Jonkman Microblog content and data are available under the Creative Commons Attribution 3.0 license.