logoalt Hacker News

yxl448last Saturday at 2:48 PM2 repliesview on HN

it is indeed disposable and the prefix is like your secure key. it is safe unless someone has access to your screen. I can add an option to permit a single session.


Replies

gruezlast Saturday at 11:09 PM

>it is safe unless someone has access to your screen

It's not, because the "secure key" is only in the domain name, which is transmitted in the clear via SNI. That means anyone along the network path can get the key, and therefore can get access in your terminal.

show 1 reply
stogotlast Saturday at 6:32 PM

I would argue that it should be the default option. Cool idea!