TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Bad Security at Evite

13 pointsby ardellabout 16 years ago

5 comments

fallentimesabout 16 years ago
Use Anyvite.<p><a href="http://anyvite.com" rel="nofollow">http://anyvite.com</a>
swombatabout 16 years ago
Didn't we have this discussion about password hashing already a few weeks ago?<p>If someone's snooping on your email, I think you've got bigger problems than a lost password, tbh.<p>As for hashing, again, if someone can get on the server and download the whole database, you've got bigger problems than password hashing.<p>I'm not saying this is a good practice, but I just don't think it's as big a problem as this guy is making it out.<p>Also, there's a balance between security and usability. For some kinds of users, not being able to tell them their password is actually a problem. Sites that are able to do that will have a competitive edge in getting those users. So the question is one of balance between usability and security, not just one of security.
评论 #498304 未加载
评论 #498365 未加载
lackerabout 16 years ago
Evite is willing to sacrifice security for usability. Which makes sense, because it doesn't really matter if someone hacks your Evite account.
评论 #498584 未加载
staunchabout 16 years ago
Sending your password after signup doesn't necessarily mean they're storing it permanently.
评论 #498562 未加载
评论 #498517 未加载
seijiabout 16 years ago
Progressive postal-mailed me a letter with password on it when they sent my first insurance cards.<p>I think some health insurance sites do the same thing.