Am 05.08.2011 23:54, schrieb Lukas Fleischer: > [1] http://projects.archlinux.org/aur.git/commit/?id=1e7b9d57 > [2] http://projects.archlinux.org/aur.git/commit/?id=5ea9fc19 > [3] http://projects.archlinux.org/aur.git/commit/?id=973e4f85 > [4] http://projects.archlinux.org/aur.git/commit/?id=89721137
Those commits are nothing but a charade. The very least you must do is this: 1) ALWAYS force a redirect to https on the AUR login page, never allow the login to be submitted unencrypted. 2) Ensure that the cookie is never sent over http, only over https. Everything less than that is completely irresponsible.
signature.asc
Description: OpenPGP digital signature