Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Just did some research, and you're right! TLS obscures the URL by default. I didn't know that.

Only nuance being that an attacker can draw conclusions about the length of the URL- which won't be very helpful on Github.



TLS alone is not sufficient. Fortunately, Github is also on the HSTS preload list.


> length of the URL

Also the length of the response, which is significantly more 'helpful', although probably not enough for a working attack unless you're willing to harrass a significant fraction of your intellectual workforce over false positives.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: