XiaoCongGame / sdk-smart-lib

The Android library project for Xiaocong SDK
0 stars 1 forks source link

Security: Xiaocong OAuth2 #6

Closed thedmd closed 2 years ago

thedmd commented 10 years ago

While logging to Xiaocong I noticed whole network traffic use unencrypted http protocol. In consequence user and password are send as plain text in url and can be easily intercepted.

ReDreamport commented 10 years ago

Sorry, I don't support HTTPS yet. But we are working on it.