3 ms·
This is really cool, however I found one major flaw that will prevent me from using this: I have a marvel.com account and forgot my password, so I went to "Forg
by jbarrow 12y ago
This is really cool, however I found one major flaw that will prevent me from using this: I have a marvel.com account and forgot my password, so I went to "Forgot my Password" to get a new one.
I was emailed with my email and password in plain text, meaning that Marvel stores the passwords in plain text. Knowing that, I'm not sure how comfortable I would be building something on top of this API.
- nly 12y agoWhile concerning with regard to their stance on security, you should really assume all web services store their passwords in plaintext. Passwords have always been kept in confidence on the web, without any guarantee of secrecy. Until web standards improve and address this with client side hashing this is an uphill battle, like trying to get people to use prepared queries instead of escaping. Use a password manager with a random per-site generator and just accept it.