5 ms·
My jaw dropped. How does such a publicly visible website think it is okay to show users their password without them asking? It should now be assumed that every
by fruchtose 14y ago
My jaw dropped. How does such a publicly visible website think it is okay to show users their password without them asking?
It should now be assumed that every hacker on the planet knows about this vulnerability, and Pandora will see attacks against their database very soon. What we don't know is if Pandora is storing users' passwords in plaintext. It is possible that Pandora remembers your password server-side for your session. I hope that this is the case. If it turns out to be anything else--plaintext passwords in database, etc.--then Pandora is worse than LinkedIn.
- qq66 14y agoWhat kind of profitable attacks could one perform with a large collection of Pandora passwords? The best I can think of is for a small band to have millions of people "like" them.
- timo614 14y agoMany users reuse passwords across their web presence. So there's the chance of gaining access to other accounts as a result of the data leak... such as their bank accounts, etc.
- bduerst 14y agoPeople typically use variants of the same password across the web. It's a huge starting place for breaking into an email account. Also, since it's vanilla http, you could sniff these passwords at a coffee shop's wifi all day and just wait for someone to log in to Pandora.
- JohnsonB 14y agoSimple, for every user that the hackers have, try their password for the associated email account, guaranteed they will gain access to many email accounts. Now they have access to their banking accounts.
- ryanwaggoner 14y agoThis could happen, but do we have any evidence that it has? I'm being serious...I constantly hear about widespread leaks of passwords, but the most I hear about it is people having their email hacked by a botnet to...send spam. Have their been any large scale attacks to gain access to bank accounts to then clean them out somehow? On top of that, how does getting access to someone's bank account even help you? You have to transfer the money to another account, which leaves a trail...
- jschmitz28 14y agoRobbing a convenience store at gunpoint or illegally downloading torrents usually also "leave a trail." That doesn't mean nobody is willing to do it, and I definitely wouldn't feel safe if random people had access to my bank account just because if they did anything law enforcement might be able to catch them.
- masterzora 14y agoI'm sorry please be clear: is your response to "this is a well-known security problem with easy-to-implement best practices to lower chances of incident" really "I've never heard of an attack using this"?
- thaumaturgy 14y agoYes. One of our clients had their ETrade account compromised after a Yahoo password leak. (We had helped them change passwords on all their other services and recover the data deleted from their Yahoo account, but they forgot they had an ETrade account.) In that case, E*Trade detected the activity as fraudulent, so the damage was minimal.
- stcredzero 14y ago> This could happen, but do we have any evidence that it has? I'm being serious...I constantly hear about widespread leaks of passwords, but the most I hear about it is people having their email hacked by a botnet to...send spam. The more password databases are hacked, the better password cracking becomes, and the more sites black hats get access to. It's a vicious cycle. Yes, people sometimes do get large amounts withdrawn from bank accounts.
- mrpollo 14y agoEven if they are just using saving it in session they aren't using https
- fruchtose 14y agoThat makes it even worse then. Every Pandora user connected via WiFi is at risk. I wonder if Pandora is usable in airports?
- samspot 14y agoIt has to be plaintext in the db, because they can't reverse the hash back to plaintext to send to you.
- pbreit 14y agoNot quite true. It could be (and probably is) encrypted in the database.
- ghayes 14y agoThat doesn't make sense. Three days after you sign-up (i.e. no cache), if they are sending you your password, it can only be because it's plaintext. Unless they are bruteforcing the hash for your convenience... :-)
- pbreit 14y agoThey could two-way encrypt which seems safer to me than plain text but some disagree (I'm not sure why).
- Evbn 14y agoOnly if the keys are well controlled.
- NateDad 14y agoIf the keys were well controlled, you wouldn't have to worry about plaintext passwords in the DB either. But passwords get leaked all the time. If the key is sitting somewhere locally, when they break in to steal the passwords, they can steal the key too. There's no way the program can reverse the password without having the key pretty easily accessible.
- samspot 14y agoCan you elaborate? I don't know any way to take a hashed password and get the plaintext version. When you log into any app i've worked on, we hash the pw you send and match it with the one in the db. This is why you have to get a password reset most of the time, because the company literally does not know your password.