this post was submitted on 09 Jul 2023
1354 points (99.0% liked)

Ask Lemmy

26858 readers
2273 users here now

A Fediverse community for open-ended, thought provoking questions

Please don't post about US Politics. If you need to do this, try !politicaldiscussion@lemmy.world


Rules: (interactive)


1) Be nice and; have funDoxxing, trolling, sealioning, racism, and toxicity are not welcomed in AskLemmy. Remember what your mother said: if you can't say something nice, don't say anything at all. In addition, the site-wide Lemmy.world terms of service also apply here. Please familiarize yourself with them


2) All posts must end with a '?'This is sort of like Jeopardy. Please phrase all post titles in the form of a proper question ending with ?


3) No spamPlease do not flood the community with nonsense. Actual suspected spammers will be banned on site. No astroturfing.


4) NSFW is okay, within reasonJust remember to tag posts with either a content warning or a [NSFW] tag. Overtly sexual posts are not allowed, please direct them to either !asklemmyafterdark@lemmy.world or !asklemmynsfw@lemmynsfw.com. NSFW comments should be restricted to posts tagged [NSFW].


5) This is not a support community.
It is not a place for 'how do I?', type questions. If you have any questions regarding the site itself or would like to report a community, please direct them to Lemmy.world Support or email info@lemmy.world. For other questions check our partnered communities list, or use the search function.


Reminder: The terms of service apply here too.

Partnered Communities:

Tech Support

No Stupid Questions

You Should Know

Reddit

Jokes

Ask Ouija


Logo design credit goes to: tubbadu


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] nudelbiotop@feddit.de 30 points 1 year ago* (last edited 1 year ago) (2 children)

Anyone who has access to any involved network infrastructure can trace the cleartext communication and extract the credentials.

[–] walkwalkwalkwalk 2 points 1 year ago (1 children)

What do you mean by any involved network infrastructure? The URI is encrypted by TLS, you would only see the host address/domain unless you had access to it after decryption on the server.

[–] apazzy@lemmy.world 8 points 1 year ago (1 children)

They said clear text, I would assume it's not https.

[–] walkwalkwalkwalk 5 points 1 year ago* (last edited 1 year ago) (1 children)

The comment we are replying to is asking about a situation where there is TLS. Also using clear text values in the URI itself does not mean there wouldn't be TLS.

[–] apazzy@lemmy.world 2 points 1 year ago

When someone just says cleartext, I assume they mean transmission too.

OP replied confirming HTTP: https://lemmy.world/comment/1033128