in reply to Encrypting or Hiding Certain Info in a URL

i don't know how you're building the URL, but you should be using POST and not GET to send the information. that will 'hide' the variables in the URL.
  • Comment on RE: Encrypting or Hiding Certain Info in a URL

Replies are listed 'Best First'.
Buzzcutbuddha: (Post Doesn't Hide Info)-RE: Encrypting or Hiding Certain Info in a URL
by buzzcutbuddha (Chaplain) on Aug 03, 2000 at 15:34 UTC
    To be technically correct, Post does not hide the information in the URL, it sends the form information in the HTTP headers apart from the URL.

    It is still possible to intercept those headers and grab the username and password, so use of session variables and cookies adds a level of security, and SSL is better.

    Just don't want anyone to get confused about the differences between GET and POST. Cheers!