TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How to out a MAJOR online company storing passwords in plaintext?

6 点作者 dwelch2344将近 10 年前
I recently became aware of a major online hotel broker that stores passwords as plaintext in their system. The management is aware of the technical risks and liabilities but has pushed off technical fixes for YEARS. Furthermore, the features of the website make it obvious that this could be q very valuable attack vector as the reset feature emails you your current plain text password.<p>So the question is: what is the ethical way to raise the issue and force their hand in a fix?<p>(Sorry for brevity and spelling; mobile on holiday)

2 条评论

paulhauggis将近 10 年前
How do you know it&#x27;s actually plain text? There are plenty of 2-way encryption methods out there.<p>Do you work there? If so, are you willing to lose your job over it?<p>These sorts of leaks can have devastating effects on the company&#x2F;customers. You should also think about the employees that work there as well. Are you willing to risk their jobs in the event that the company loses money?
评论 #9636503 未加载
评论 #9636712 未加载
评论 #9636715 未加载
dublinben将近 10 年前
Anonymously report to plaintextoffenders.com?