HN
Hacker News
Top
New
Best
Ask
Show
Jobs
Comment by wtetzner | Hacker News Reader
Parent
Full thread
wtetzner
·
You don't store your password in the URL.
View on HN
someonebaggy
·
I store my session token in a cookie, which is even worse because it's sent with every request.
SahAssar
·
It's not. The cookie only gets sent to the domains/servers you specify and is not accidentally exposed via browser history or copying a link.
bsharper
·
Not in a URL generally, and if it is the only people who can see the full URL are the receiver and the sender if HTTPS is properly enabled.
Reply on news.ycombinator.com