From 1119063c69eb4fc091c212e59462f3ec3d5676a4 Mon Sep 17 00:00:00 2001 From: Sam Thursfield Date: Mon, 30 Mar 2015 11:25:51 +0100 Subject: [PATCH] Fixed #24556 -- Added reminder about HTTPS to passwords docs. --- docs/topics/auth/passwords.txt | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/docs/topics/auth/passwords.txt b/docs/topics/auth/passwords.txt index 910d08fabe..5f7bece6ee 100644 --- a/docs/topics/auth/passwords.txt +++ b/docs/topics/auth/passwords.txt @@ -8,6 +8,14 @@ tools for managing user passwords. This document describes how Django stores passwords, how the storage hashing can be configured, and some utilities to work with hashed passwords. +.. seealso:: + + Even though users may use strong passwords, attackers might be able to + eavesdrop on their connections. Use :ref:`HTTPS + ` to avoid sending passwords (or any other + sensitive data) over plain HTTP connections because they will be vulnerable + to password sniffing. + .. _auth_password_storage: How Django stores passwords