From 5cc0407e45393d24dee2303847902859bebda951 Mon Sep 17 00:00:00 2001 From: Sam Thursfield Date: Mon, 30 Mar 2015 11:25:51 +0100 Subject: [PATCH] [1.8.x] Fixed #24556 -- Added reminder about HTTPS to passwords docs. Backport of 1119063c69eb4fc091c212e59462f3ec3d5676a4 from master --- docs/topics/auth/passwords.txt | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/docs/topics/auth/passwords.txt b/docs/topics/auth/passwords.txt index ee41c4bcdb..20559ed5d4 100644 --- a/docs/topics/auth/passwords.txt +++ b/docs/topics/auth/passwords.txt @@ -8,6 +8,14 @@ tools for managing user passwords. This document describes how Django stores passwords, how the storage hashing can be configured, and some utilities to work with hashed passwords. +.. seealso:: + + Even though users may use strong passwords, attackers might be able to + eavesdrop on their connections. Use :ref:`HTTPS + ` to avoid sending passwords (or any other + sensitive data) over plain HTTP connections because they will be vulnerable + to password sniffing. + .. _auth_password_storage: How Django stores passwords