← Back to context

Comment by tyingq

8 years ago

Sounds bad to me...

"We've discovered (and purged) cached pages that contain private messages from well-known services, PII from major sites that use cloudflare, and even plaintext API requests from a popular password manager that were sent over https (!!)."

The trouble is you have no way to know if someone discovered this earlier, and harvested info for a long time.

Or, how much harvested info from your site might be in a Google cache for someone else's site.

Does 1Password really send anything meaningful in their API queries, or is it encrypted separately and then just sent over HTTPS?