我在盐 + 密码上使用 SHA-512 哈希 1000 次。在查询有关用户的信息时返回它是否安全,或者我应该保护它并使其仅通过 HTTPS 可用?
例如,如果我提出以下请求:
GET: http://domain.com/users?id=437
它返回:
{"firstName":"Eliot","lastName":"My last name","email":"email@emailplace.com","password":[91,49,-34,77,79,-48,67,-62,-12,84,84,-18,-81,23,-92,-31,74,-28,-80,102,60,35,-102,115,18,-76,20,-90,-8,91,13,23],"authToken":"33c977b1-5ab6-4a8a-8da9-68c8028eff92","id":179}
公之于众有什么关系吗?