OWASP / wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
https://owasp.org/www-project-web-security-testing-guide/
Creative Commons Attribution Share Alike 4.0 International
6.96k stars 1.3k forks source link

Merge of Sensitive Information and Credentials Transport in Clear Text #598

Open ThunderSon opened 3 years ago

ThunderSon commented 3 years ago

What would you like to happen? Merge ATHN-01 and CRYP-03 as they represent in their entirety the same thing, just different terms (credentials versus sensitive info).

kingthorin commented 3 years ago

Agreed in 2013/2014 before the drive toward all HTTPS all the time it made sense for them to be split. Today, however, it probably makes sense for credentials to just be another type of "sensitive information". So lumping them both together makes sense to me. I'd be fine with ATHN-01 being chopped and it's content merged into CRYP-03. (A lead-in (0th page) for 4.4 could be added that clarifies this.)

github-actions[bot] commented 3 years ago

Please comment if you are still working on this issue, as it has been inactive for 30 days. To give everyone a chance to contribute, we are releasing it to new contributors.

github-actions[bot] commented 3 years ago

Please comment if you are still working on this issue, as it has been inactive for 30 days. To give everyone a chance to contribute, we are releasing it to new contributors.

github-actions[bot] commented 3 years ago

Please comment if you are still working on this issue, as it has been inactive for 30 days. To give everyone a chance to contribute, we are releasing it to new contributors.

github-actions[bot] commented 2 years ago

Please comment if you are still working on this issue, as it has been inactive for 90 days. To give everyone a chance to contribute, we are releasing it to new contributors.

github-actions[bot] commented 2 years ago

Please comment if you are still working on this issue, as it has been inactive for 90 days. To give everyone a chance to contribute, we are releasing it to new contributors.

manindar-mohan commented 1 year ago

i will take this up.