6 ms·
POST can be sniffed and is only slightly less vulnerable than GET. HTTPS at a dedicated address should be a minimum level of security for a login form. Anything
by badmonkey0001 15y ago
POST can be sniffed and is only slightly less vulnerable than GET. HTTPS at a dedicated address should be a minimum level of security for a login form. Anything else is readily vulnerable to sniffing or spoofing.
- stcredzero 15y agoProperly implementing hashed passwords with challenge-response will protect your login, though your session information can still be sniffed.