Friday, 18 February 2011

How Secure Are Query Strings Over HTTPS?

The original article is from HttpWatch's blog, a very good post. So, to make a long story short, the conclusions are: At the network level, HTTPS URL parameters are secure, but there are some other ways in which URL based data can leak:
  1. URLs are stored in web server logs,
  2. URLs are stored in the browser history,
  3. URLs are passed in Referrer headers