5 ms·
He claims to have notified Criticker in 2010, and links to a post on their forum (username teario): http://www.criticker.com/forum/viewtopic.php?f=8&t=2063#p18
by pille 13y ago
He claims to have notified Criticker in 2010, and links to a post on their forum (username teario):
http://www.criticker.com/forum/viewtopic.php?f=8&t=2063#p18825 http://www.criticker.com/forum/viewtopic.php?f=8&t=2063#p188...
- LukeB_UK 13y agoThanks for that, I skipped over that paragraph.
- CatMtKing 13y agoI don't think his post was blatant enough for the devs to pick up on it. Seems like the only guy that responded tl;dr'd it. He should have stated very clearly that this is a MAJOR security issue.
- makaveli8 13y agoAgreed - He didn't even say that it was an issue at all. He seemed more concerned that the users are scoped to particular API keys and that he will lose his reviews.
- 6cxs2hd6 13y agoFrom a quick glance at their forums, there are no posts about this (yet). It will be interesting to see how users feel about this. It will also be interesting to see if the company makes any warning that the average user will understand (e.g. "don't reuse your Criticker password on other sites, especially email or financial, because your password here is not secret, at all").