Shop.charliesoap.com sending unencypted passwords to browsers

https://news.ycombinator.com/item?id=4785813
by visualcsharp • 14 years ago
1 0 14 years ago

Yep. I just noticed this as I logged in to update my email address. I saw that the password field was actually populated with something so I checked the markup. Sure enough, there was my [fortunately unique and randomly-generated] password in plain text. That means whoever coded their shopping Web site is most likely storing passwords in plain text in a database. I've sent them two messages about this.

Related Stories

Loading related stories...

Source preview

news.ycombinator.com