Live data from Hacker News

I don't want the notice of insecure password/log-in on my website

bugzilla.mozilla.org

1–10 of 13 posts

Re: I don't want the notice of insecure password/log-in on my website

#5
post #3

Oh no.. they've locked it to authorised users only. Anyone get a screengrab?

Also this reddit thread is interesting; looks like someone already dropped their user table. Which may have been for the best considering it appears that they stored passwords in plain text (then again I'm sure someone dumped it before dropping it).

https://www.reddit.com/r/programming/comments/60jc69/company...

Re: I don't want the notice of insecure password/log-in on my website

#6
Quick question regarding this security pop-up. I don't have much experience with the security side of things apart from HTTPS certs/etc, but isn't Dell's NZ website a bit iffy?

i.e. dell.com/nz/ -> 'My Account' looks like it's done over plain HTTP. Is my assumption correct?

Re: I don't want the notice of insecure password/log-in on my website

#9
I think they broke all the best-practices to make websites [1]:

> Update: Around the same time this post was going live, participants of this Reddit thread claimed to hack the site using what's known as a SQL injection exploit.

> Multiple people claimed that passwords were stored in plaintext

> the site's subscription page transmits credit card information over plain-vanilla HTTP pages as well.

[1] https://arstechnica.com/security/2017/03/firefox-gets-compla...

Re: I don't want the notice of insecure password/log-in on my website

#10
post #3

Oh no.. they've locked it to authorised users only. Anyone get a screengrab?

http://archive.is/53Cbd

>> Your notice of insecure password and/or log-in automatically appearing on the log-in for my website, Oil and Gas International is not wanted and was put there without our permission. Please remove it immediately. We have our own security system and it has never been breached in more than 15 years. Your notice is causing concern by our subscribers and is detrimental to our business.

Oh my... HTTPS was already well established 15 years ago... are people like this in charge of nuclear facilities, too?

Post reply on HN