TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Bad Security at Evite

13 点作者 ardell大约 16 年前

5 条评论

fallentimes大约 16 年前
Use Anyvite.<p><a href="http://anyvite.com" rel="nofollow">http://anyvite.com</a>
swombat大约 16 年前
Didn't we have this discussion about password hashing already a few weeks ago?<p>If someone's snooping on your email, I think you've got bigger problems than a lost password, tbh.<p>As for hashing, again, if someone can get on the server and download the whole database, you've got bigger problems than password hashing.<p>I'm not saying this is a good practice, but I just don't think it's as big a problem as this guy is making it out.<p>Also, there's a balance between security and usability. For some kinds of users, not being able to tell them their password is actually a problem. Sites that are able to do that will have a competitive edge in getting those users. So the question is one of balance between usability and security, not just one of security.
评论 #498304 未加载
评论 #498365 未加载
lacker大约 16 年前
Evite is willing to sacrifice security for usability. Which makes sense, because it doesn't really matter if someone hacks your Evite account.
评论 #498584 未加载
staunch大约 16 年前
Sending your password after signup doesn't necessarily mean they're storing it permanently.
评论 #498562 未加载
评论 #498517 未加载
seiji大约 16 年前
Progressive postal-mailed me a letter with password on it when they sent my first insurance cards.<p>I think some health insurance sites do the same thing.