4 ms·
I'd like to believe that. However, I was recently asked to test a new website for an organization I volunteer for, and discovered their "forgot password" flow e
by throwaway34916 10y ago
I'd like to believe that. However, I was recently asked to test a new website for an organization I volunteer for, and discovered their "forgot password" flow emailed me my plaintext password. I wrote an explanation of why this was bad, and how it could be fixed, to a non-technical friend of mine who works there; he passed my email to the (Bay Area based!) consulting shop that did their website. The shop sent this response:
"We do not store passwords as a plain text in database. We have functionality which encrypts and decrypts passwords. We have only ecnrypted passwords in the database.
Almost all other servers use one-way encryption. In this case, passwords cannot be decrypted from hashing."
Again, this is a Bay Area based shop. For code written in 2016.
I was shocked to receive this, but it (among other things) leads me to suspect that there are lot of people out there, in positions of power, who aren't just ignorant, but who actively cling to password-storage anti-patterns.
I'm at a loss for how to fix this.
- crazypyro 10y agoJust for clarity, the "forgot password" flow emailed you the current password of the account (not a temporarily one)? That's insane...
- throwaway34916 10y agoYes, the current password.
- wtfishackernews 10y agosubmit the website to http://plaintextoffenders.com/ http://plaintextoffenders.com/
- syncsynchalt 10y agoIronically, hosted on a Y! site.