5 ms·
I'll never visit an envato site again, let alone pay for any of their services. I can understand everyone gets hacked, but cleartext! wtf.
by blissofbeing 14y ago
I'll never visit an envato site again, let alone pay for any of their services. I can understand everyone gets hacked, but cleartext! wtf.
- charliesome 14y agoFrom the article: Tuts+ Premium is the only Envato service that operates with cleartext passwords, and it was a known internal issue for us, with a plan currently in progress to upgrade away from the current plugin.
- pwny 14y agoStill, this not being priority number one for them (before even making this service public!) means I will never do business with them. It says a lot about how they value their customers.
- bluetidepro 14y ago"plan currently in progress" - A bit late, don't you think?
- whichdan 14y agoThe sad thing is, it's completely trivial and non-disruptive to switch to from a cleartext database to a hashed+salted one.
- Xylakant 14y agoNot if you depend on a software that requires plaintext passwords (as they obviously do). Whether it's a wise choice using such a software is open to discussion though.
- 16s 14y agoSometimes business/marketing managers and IT security managers disagree. Looks as though the business guys trumped the security guys on this one. That happens a lot in the real world.
- Xylakant 14y agoSince there's no such thing as absolute security, all security effort is a balance between an assumed threat and the havoc it could create and costs. So it's always business vs. security. I'm a bit on the fence here and I guess I'd have taken another route but well, if the product was not viable without the plugin... Who knows. Given that: My remark was directed at the blank statement that it's always easy to switch. It obviously is not in that case, the change was on the agenda [1], so it's a bit tough that this happened in the meantime. [1] At least according to the official statement. I don't have any reason to believe otherwise.
- tylermenezes 14y agoIt's not like it's hard for a site which offers programming tutorials to just change the password storage method.