Hacker News new | ask | show | jobs
by hn_acker 886 days ago
If you're using a third-party reverse proxy, then the third party will have access to the user's password. What's the simplest way to prevent the third-party from knowing the password? Would adding an encryption layer between the user and the actual website owner be both feasible and sufficient for the average website owner?
1 comments

Don't use reverse proxies you don't trust