Advertisement
Promo

Security threats Toolkit

Story: Microsoft IE patch leaves users locked out

  • Previous comment

Posted by: S. (Thursday 5 February 2004, 10:02 AM)

  • Reply

It's perfectly valid to pass username and password in a URL - eg over SSL, or within an otherwise secured network.

[schema]//[user]:[password]@[host]:[port]/[url-path]

is defined in RFC 1738.

The staggering thing *should* be that a major software vendor specifically denies its installed base access to accepted standard mechanisms as a workaround for its own inadequacies. But hey, what else is new.

  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread

Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters