Windows 8 and 8.1 Forums


Transmitting encrypted passwords in the URL - BAD idea

  1. #1


    Hafnarfjörður IS
    Posts : 4,376
    Linux Centos 7, W8.1, W7, W2K3 Server W10

    Transmitting encrypted passwords in the URL - BAD idea


    Hi there
    sometimes when web sites logon automatically with your password - these passwords have to be stored somewhere - and transmitted. Since these are often transmitted in the URL anybody can intercept your data if they are so inclined - so a hacker doesn't even NEED to use any password cracking technology -- just using your data stream presumably they could logon to your Bank account and empty it.

    Maybe I'm being paranoid here or have I totally misunderstood how the system works but the password (encrypted) has to be transmitted in the data sent to the target website and most of the data string is initially sent as a string in the URL.

    Hopefully someone here can explain either is this TRUE - or is it FALSE. In any case especially with Banks etc I always set to completely logoff -- however it doesn't prevent the essential weakness that a string is sent to the target web site over the public Internet and this string can be intercepted - and replicated.

    (As an Engineer we often used to use things like Datascopes to analyse / read the data streams that were being sent / received over various devices so the technology is there to capture this stuff -- it's been around since the late 1960's !!!).

    Cheers
    jimbo

      My System SpecsSystem Spec

  2. #2


    When using the HTTPS protocol all data sent to or received from the site is encrypted, thus making interception very difficult.
    See this article for more information:
      My System SpecsSystem Spec

Transmitting encrypted passwords in the URL - BAD idea
Related Threads
Hi all: I have a client that purchased 9th Edition Inch Fastener Standards-2014c-Digital (PDF) that uses a KEYLOK usb thumb drive in order to open the PDF. Now for the problem... when I open it abode reader opens then it says initializing and gets stuck at about 5%. This happens on two of my...
encrypted image backup and perform a restore? in Performance & Maintenance
As one proceeds to create a complete system image encrypted ? 've Got no success for two veses . One with TrueCrypt and another with BitLocker.
Hi folks, Clue is in the title. Have a toshiba laptop with the UEFI encrypted windows 8 key. The hard drive was broken as it was dropped. No sticker on the bottom as is now microsoft policy. Download of the windows install needs the windows key. Cant get it as it's encrypted. Found generic...
Hi all, I got a new Toshiba Satellite L50-B notebook with Windows 8.1 64-bit installed. As I need to go a special place, I passed the notebook to a IT guy and have the whole disk encrypted using DiskCryptor. The guy told me that he cannot boot the OS, even he entered the correct password. And...
I may need some help :huh: See, my little brother accidentally formatted an encrypted partition of my HDD (Disk drive D: 100 GB to be exact) which contained really important data that I need back! It had all of my photographs from the past 5 years (which I was too lazy to back up on cloud...
Encrypted files and lost user account in User Accounts and Family Safety
I have some encrypted files that were encrypted under a windows8 account that got corrupted by the 8.1 update. I had to delete the account and recreate it. I created the same User ID and same PW but I can't decrypt the files now... I swore I've done that before and regained access to the...
So it looks like MS went and encrypted the UIFiles. That means no editing the twinui.dll, explorerframe.dll, authui.dll, and others at all. I tried injecting an unencrypted UIFile into a dll and it crashed windows. Im sure HEX editing might still be possible, but it looks like MS really...
Eight Forums Android App Eight Forums IOS App Follow us on Facebook