4 ms·
Be careful with JavaScript and saving plain text passwords in cookies: http://cookie.pen.io http://cookie.pen.io I just stole your password. :) <img src=
by ElbertF 16y ago
Be careful with JavaScript and saving plain text passwords in cookies:
http://cookie.pen.io http://cookie.pen.io
I just stole your password. :)
<img src="" onerror="alert(document.cookie.replace(/^.+pw=([^;]+);.+$/, '$1'));">
- deleted 16y ago[deleted]
- olalonde 16y agoNice reminder to use throw away passwords on untrusted sites. (no offense feint)
- feint 16y agosorry my mistake and thanks for picking it up. Passwords are now hashed and working on the js now
- bmelton 16y agoI'm not an expert in these sorts of things, but even that is probably asking for trouble (though considerably less so.) What's worked for me in the past was to generate a random string each time I create a session for the user, which is valid to create exactly one session for the user. That string is consumed with each use and a new one is generated and saved to the cookie (which again, is good for the NEXT login.) I'm sure it's also far from perfect, and causes potential havoc for users switching devices, and that sort of thing (though, where I've applied it, that was considered a feature, not a bug -- YMMV). Back on subject, Pen.IO looks money, but I'd be worried about running out of page names fairly quickly. Have you thought about tying those to an account? bmelton.pen.io/test isn't quite as good as test.pen.io, but in 3 months, I don't like the odds of getting a page name less than 10 characters... and this problem only gets worse as you get more popular.
- JoachimSchipper 16y agoSee http://searchyc.com/bcrypt http://searchyc.com/bcrypt. Really, you can't do crypto in Javascript - see e.g. http://rdist.root.org/2010/11/29/final-post-on-javascript-crypto/ http://rdist.root.org/2010/11/29/final-post-on-javascript-cr....
- dansingerman 16y agoWhy do you need to store a password in JS at all?