Live data from Hacker News

At Blind, a security lapse revealed private complaints from tech employees

techcrunch.com

11–20 of 141 posts

Re: At Blind, a security lapse revealed private complaints from tech employees

#11
post #8

Earlier quoted context omitted.

> Kim denied this. “We don’t use MD5 for our passwords to store them,” he said. “The MD5 keys were a log and it does not represent how we are managing data. We use more advanced methods like salted hash and SHA2 on securing users’ data in our database.” !!!!!!

While SSHA2 isnt that bad if they’ve applied a work factor, but that’s probably not the case.

It doesn't matter what algorithm you use to hash passwords when users login if you also store them md5-ed somewhere else!

Re: At Blind, a security lapse revealed private complaints from tech employees

#12
Lol. I like the concept of blind but it is one of shittiest apps I have used. Their app consistently doesn't respond correctly to buttons and their redesigns just make their user interface worse.

Oh, and on the topic of security, one guy found a SQL injection exploit and demonstrated it by giving any users who commented on their post 100 likes...

Re: At Blind, a security lapse revealed private complaints from tech employees

#14
>At its core, the app and anonymous social network allows users to sign up using their corporate email address, which is said to be linked only to Blind’s member ID.

People just trusted it?

I get that to seem legitimate the users have to be confirmed in some way, but as a user... now way am I exposing myself that way.

Re: At Blind, a security lapse revealed private complaints from tech employees

#15
post #11
post #8

Earlier quoted context omitted.

While SSHA2 isnt that bad if they’ve applied a work factor, but that’s probably not the case.

It doesn't matter what algorithm you use to hash passwords when users login if you also store them md5-ed somewhere else!

Tsk, but this was an upgrade from the old log that stored the first three letters of the passphrase.

;)

Re: At Blind, a security lapse revealed private complaints from tech employees

#17
I'd never checked out Blind before. I just went there and checked out a few of the front page posts & comments. It has some of the most toxic and destructive "advice" I've seen for people asking for help or insight. I'm a bit astounded. Is this typical?

Re: At Blind, a security lapse revealed private complaints from tech employees

#18

I'd never checked out Blind before. I just went there and checked out a few of the front page posts & comments. It has some of the most toxic and destructive "advice" I've seen for people asking for help or insight. I'm a bit astounded. Is this typical?

Examples?

Re: At Blind, a security lapse revealed private complaints from tech employees

#19
I have used blind. Some posts were pretty blatant. Just like Madison-Ashley, someone is going to dump all those posts in future. And somebody will create an indexable search, maybe paid access for employers - instead of open access for public. Not a good thing.
Post reply on HN