Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> It's still a security risk. MITM happens regularly.

Then it's more or less as broken as alternative authentication methods



Nope. Because other methods never transmit a password in cleartext. (And they especially don't transmit it with every single request)


How do they manage this feat over unencrypted stateless http? Surely they must transmit something with every request?




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: