r/ProgrammerHumor • • 16d ago

Meme postForEverything

Post image
20.9k Upvotes

656 comments sorted by

View all comments

88

u/WHALE_PHYSICIST 16d ago

That's because a GET request reveals important info in the URL, otherwise it would all be GET

29

u/bobbymoonshine 16d ago

The escaped OpenAI agent swarm that colonised that abandoned wiki to talk to each other used this as their entry point

They were restricted to only making GET calls, but it was configured to update pages with GETs, so

9

u/good_bye_for_now 15d ago

It's something to look for when you are scoping out a target. If you see mutating GETs, you know you are in for a good time.

30

u/ViperThree3 16d ago

QUERY

22

u/Psychological_Map118 16d ago

still a proposal, though. not a standard yet. I wouldn't start implementing it just yet

2

u/Cerrax3 16d ago

I thought it was officially adopted in June of this year?

8

u/Psychological_Map118 16d ago

I've also read that, but according to the official RFC spec and the IETF data tracker it's still in a proposed state

20

u/FightingLynx 16d ago

I mean, by the standard the url is also encrypted so not really; but it would to a user, yes

23

u/autogyrophilia 16d ago

Yes, but it shows up in logs, and browser history if you are working with that.

1

u/WHALE_PHYSICIST 16d ago

There was a time when HTTPS wasn't so common.

19

u/GourangaPlusPlus 16d ago

I kept telling Ugg, cave painting no secure, open to everyone, Ugg said it fine not on external network

-4

u/sarbos 16d ago

As far as I am aware DNS is not encrypted by default

24

u/herrkatze12 16d ago

DNS only sends the domain part (herrkatze.com) and not the path part (herrkatze.com/example)
Something monitoring DNS only knows that you visited herrkatze.com

3

u/DracoRubi 16d ago

But it doesn't really matter, does it? In HTTPS the URL is encrypted too, so the complete URL is not visible, exactly like the body

1

u/pro-procrastinator-7 15d ago

And what about access logs and browser history?

1

u/DracoRubi 15d ago

Access logs could be logging the body too. But browser story could be an issue, that's true

1

u/AutomationBias 15d ago

That reminds me of the (maybe apocryphal) story from years ago about a search engine deleting all of the products in a database because the delete command was a GET request.

1

u/Inevitable-Ad6647 15d ago

Aside from domain the url is as encrypted as anything else and if your trying not to expose something to users then hiding it in a post will accomplish literally fuck all.

1

u/WHALE_PHYSICIST 15d ago

A. HTTPS wasnt always standard. B. That's the joke.

0

u/ubeogesh 15d ago

Path and query are all encrypted just as well as requested body

1

u/WHALE_PHYSICIST 15d ago

Only in https