Hacker News new | ask | show | jobs
by csbowe 3627 days ago
It's base64 encoded and put into the header, according to the article.
1 comments

But if you use HTTPS, those headers are encrypted, right?
The problem is they can end up in the logs of the receiving server and if that gets hacked...