Pandora doesn't hash their passwords
21–30 of 160 posts
Re: Pandora doesn't hash their passwords
#22Re: Pandora doesn't hash their passwords
#23Is there a need for the password to even be printed there? Usually the flow for changing the password is inputting the current password, then typing the new password twice.
But I guess that's a minor issue compared to exposing your password. Either way, the whole programming dept. at Pandora needs a lesson in passwords.
Re: Pandora doesn't hash their passwords
#24If your Pandora password is extremely sensitive perhaps you should re-evaluate how anal you are about privacy. As long as your CC details are secure, who cares?
Re: Pandora doesn't hash their passwords
#25Is there a need for the password to even be printed there? Usually the flow for changing the password is inputting the current password, then typing the new password twice.
Re: Pandora doesn't hash their passwords
#26Here is a list http://plaintextoffenders.com/
I would have expected Pandora to know better. Anytime a website shows you your password or emails it to you, it's a bad sign. It means it is stored in plain text.
The websites that do it right cannot tell you your password (because they don't know it); they can only let you reset it.
Re: Pandora doesn't hash their passwords
#27Earlier quoted context omitted.
I just checked, my password was visible in the source. Pretty shitty, Pandora.
EDIT: Found it. It was in the settings page. What is the source code surrounding the password? Is it the same as the screenshot? I'm trying to find mine but can't. Also, what browsers are you guys using? Mine is Chrome.
Re: Pandora doesn't hash their passwords
#28My jaw dropped. How does such a publicly visible website think it is okay to show users their password without them asking? It should now be assumed that every hacker on the planet knows about this vulnerability, and Pandora will see attacks against their database very soon. What we don't know is if Pandora is storing users' passwords in plaintext. It is possible that Pandora remembers your password server-side for y…
Re: Pandora doesn't hash their passwords
#29My jaw dropped. How does such a publicly visible website think it is okay to show users their password without them asking? It should now be assumed that every hacker on the planet knows about this vulnerability, and Pandora will see attacks against their database very soon. What we don't know is if Pandora is storing users' passwords in plaintext. It is possible that Pandora remembers your password server-side for y…
Re: Pandora doesn't hash their passwords
#30My jaw dropped. How does such a publicly visible website think it is okay to show users their password without them asking? It should now be assumed that every hacker on the planet knows about this vulnerability, and Pandora will see attacks against their database very soon. What we don't know is if Pandora is storing users' passwords in plaintext. It is possible that Pandora remembers your password server-side for y…
What kind of profitable attacks could one perform with a large collection of Pandora passwords? The best I can think of is for a small band to have millions of people "like" them.
So there's the chance of gaining access to other accounts as a result of the data leak... such as their bank accounts, etc.