Live data from Hacker News

Lessons in website security anti-patterns by Tesco

troyhunt.com

11–20 of 120 posts

Re: Lessons in website security anti-patterns by Tesco

#12
post #4

Earlier quoted context omitted.

If it was the weekend, it seems unlikely to me that the person running the Twitter account would have got in touch with someone with a technical understanding of how the site works. More likely they just consulted their list of talking points and picked the ones that looked most relevant to the situation.

On the other hand, the sensible thing to do would be to say something like “Can you provide your contact details in a DM: we’ll get one of our tech guys to contact you on Monday”

Yes, definitely. Having customer service respond to security complaints on Twitter really isn't very smart.

Re: Lessons in website security anti-patterns by Tesco

#13
post #9

This is a hilarious, albeit depressing, view of the state of cyber security as seen by the general public. People, even those who are generally considered computer literate, don't have any understanding of web security. Due to this, Tesco won't hit any negative publicity outside of a tight knit circle of programmers. In fact, saying that everything is "stored securely" according to "industry standards" would reassure…

If only Google Chrome would start warning users on signup that their password would be stored in plain text.

Re: Lessons in website security anti-patterns by Tesco

#14
Hey Troy, Thought you might be somewhat interested in this one. Remeber the cool guys over at http://www.realestate.com.au/ Just to refresh your memory..

https://twitter.com/#!/realestate_au/status/2207319148043059...

Anyway, "we are aware of this issue and are working on it".

Click http://www.realestate.com.au/ then "Register".

Then stand in utter amazement at their solution.

-------------------------------------------

Why do we need your email address?

     *We send your password via email.*
     *Your email address is your log on.*
     *If you forget your password, we'll send you a new one.*
-------------------------------------------

This is hilarious. I can only assume that they took offence to you choosing a "strong version" password, so they decided, how can we fix this? I know, lets just pick the password for them.

So, their fix that they told you about, was to ensure that you can't pick a password at all, and they will still email you their "super strong version password"...

> Thank you for registering. Your password has been sent to username[at]gmail.com. It should arrive shortly.

12 seconds later.

Your password is: DTCNE

(In case people aren't aware, realestate.com.au is owned by HomeAway)

Re: Lessons in website security anti-patterns by Tesco

#15
post #13
post #9

This is a hilarious, albeit depressing, view of the state of cyber security as seen by the general public. People, even those who are generally considered computer literate, don't have any understanding of web security. Due to this, Tesco won't hit any negative publicity outside of a tight knit circle of programmers. In fact, saying that everything is "stored securely" according to "industry standards" would reassure…

If only Google Chrome would start warning users on signup that their password would be stored in plain text.

Google Chrome and the Google search engine warn you if a website contains malware or is suspected of phishing. Poor security is just as dangerous as these, the only thing missing is the malicious intent.

Unfortunately, Google would likely open themselves to lawsuits if they warned users away from or penalised websites due to poor security.

Re: Lessons in website security anti-patterns by Tesco

#16
post #9

This is a hilarious, albeit depressing, view of the state of cyber security as seen by the general public. People, even those who are generally considered computer literate, don't have any understanding of web security. Due to this, Tesco won't hit any negative publicity outside of a tight knit circle of programmers. In fact, saying that everything is "stored securely" according to "industry standards" would reassure…

More than depressing I consider this to be a reality check. Procedures must be put in place for people who can't be expected to deal with this kind of thing properly.

Re: Lessons in website security anti-patterns by Tesco

#17
Whilst I agree with the big one about plain text passwords some of the niggles here seem a little odd.

Tesco are not advising that everyone goes back to IE 3, they are simply stating this as a lowest common denominator since I'm assuming that was the first browser to support whatever version of TLS they were using etc.

Also, is running an old version of ASP.NET and IIS really a problem? Does he advocate going through the expense of rewriting/retesting the entire website every time MS drops a new version? If they are pulling down security patches this should be a non issue.

Re: Lessons in website security anti-patterns by Tesco

#20

Hey Troy, Thought you might be somewhat interested in this one. Remeber the cool guys over at http://www.realestate.com.au/ Just to refresh your memory.. https://twitter.com/#!/realestate_au/status/2207319148043059... Anyway, "we are aware of this issue and are working on it". Click http://www.realestate.com.au/ then "Register". Then stand in utter amazement at their solution. ----------------------------------------…

In slight defense of that horrible password practice:

You can't really do much with a realestate.com.au account unless you are an Agent (which is a separate account). There's no payment processing, or any way to add content to the site. The accounts there are basically just a way to save common realestate searches as far as I can tell.

Post reply on HN