this post was submitted on 18 Jul 2023
5 points (100.0% liked)

Discussions related to Infosec.pub

1128 readers
1 users here now

founded 1 year ago
MODERATORS
 

I tried logging in on browser and I had inspected the request. My password was sent in plaintext. Is this a infosec.pub issue or a Lemmy one?

you are viewing a single comment's thread
view the rest of the comments
[โ€“] vedard@infosec.pub 3 points 1 year ago (1 children)

You are describing TLS, which is commonly used for websites and web apps.

Try the following command:

openssl s_client -connect infosec.pub:443

The public key, the authority that signed the certificate, and the cypher used will all be visible.

For me, the cipher used is ECDHE-RSA-AES256-GCM-SHA384.

[โ€“] iamak@infosec.pub 2 points 1 year ago

Oh. Okay. I'll check it out once. I'm pretty new to all this so I didn't know this is how SSL works.