you are viewing a single comment's thread
view the rest of the comments
[–] 35 points 3 years ago* (5 children)

Anyone who has access to any involved network infrastructure can trace the cleartext communication and extract the credentials.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 3 points 3 years ago (3 children)

    What do you mean by any involved network infrastructure? The URI is encrypted by TLS, you would only see the host address/domain unless you had access to it after decryption on the server.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 13 points 3 years ago (2 children)

    They said clear text, I would assume it's not https.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 7 points 3 years ago* (1 child)

    The comment we are replying to is asking about a situation where there is TLS. Also using clear text values in the URI itself does not mean there wouldn't be TLS.

  • source
  • parent
  • hideshow 1 child comment