Must logins be a https page

后端 未结 8 1260
無奈伤痛
無奈伤痛 2020-12-16 10:19

Several security experts have said in the past that the login page should be on ssl https. So what if my login is a block that\'s displayed on all pages. Does that mean that

相关标签:
8条回答
  • 2020-12-16 10:56

    Simple answer "Yes" your login page and rest of the websites should be served over SSL

    And here is why from SSL Implementation FAQ:

    • Can I put my Login form to HTTP and target my form to HTTPS?
    • Is it secure switch back to HTTP after login over HTTPS?
    0 讨论(0)
  • 2020-12-16 11:00

    If you want your data to be safe you have to use SSL(certified) on your whole site. But you don't need to have SSL to keep your passwords safe. You could for example use openID, facebook connect, twitter sign-in to handle this part for you. This way never passwords get sent over the wire in plain-text.

    0 讨论(0)
提交回复
热议问题