3 ms·
I think it's time for web browsers to step up and start showing a visual indication for websites that store passwords in plaintext.
by engtech 14y ago
I think it's time for web browsers to step up and start showing a visual indication for websites that store passwords in plaintext.
- wesley 14y agoHow would a browser ever know this?
- diminoten 14y agoProbably the same way they know which sites are likely to contain malware or be involved in phishing scams: user reports.
- Tipzntrix 14y agoYep. http://news.ycombinator.com/item?id=4555083 http://news.ycombinator.com/item?id=4555083 I.E. is actually the best at stopping social engineering attacks on your average consumer because of their SmartScreen technology, which relies completely on feedback from the community, both automatic and manual. No reason to downvote this or the original comment IMO.
- nathan_long 14y agoOf course the browser can't know this. But one clue for the user is if there is a strict length limit. If you're going to hash my password to 16 characters anyway, why can't I type in 20? But if you're going to store it as plaintext, you need to limit what I input.
- masklinn 14y agoAnd... how could they know exactly?
- engtech 14y agoweb browsers are doing this for malware / fraud sites. see other comments on parent for citations.
- masklinn 14y agoThat's reactive, for passwords in cleartext it's not very useful: by the time you get the news, the damage has been done already. At best it tells you to change you passwords before the site itself tells you.
- Tipzntrix 14y agoThat's a fair point. The only way it would work is if an anonymous insider reported the company before the general public knew about it. Either that or it would serve as a blacklist for companies who already made one mistake, though it's very unlikely to see them make 2 (and in Sony's case, people are still using PlayStation Network anyway).
- joshuahedlund 14y agoBrowsers can't reliably know this. Although they could probably at least figure out if the form submission is going to be a freaking GET request!