Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Comment HTTP Request Smuggling (Score 2, Informative) 168

I RTFA and the white paper. Worth mentioning here (I searched the first 108 comments and saw no mention of this):

- HTTPS is not affected

The white paper, while seemingly complete and well written, mentions this almost in passing near the end of the document. That may cause many readers, if they simply skim the paper, to miss this critical point. Further, it discounts using HTTPS as "...an impractical solution".

If security is engineered into your site from the beginning, there's nothing at all impractical about using HTTPS.

Slashdot Top Deals

If computers take over (which seems to be their natural tendency), it will serve us right. -- Alistair Cooke

Working...