The store isn't actually run by microsoft, but rather Quasar Media. It tarnishes Microsoft's name, but it isn't their fault. http://www.theverge.com/2012/2/12/2793459/microsoft-store-in...
Microsoft Store hacked in India, passwords stored in plain text
11–20 of 41 posts
Re: Microsoft Store hacked in India, passwords stored in plain text
#12Earlier quoted context omitted.
No, if you look at the characters in the UI. Still, clearly the answer is that's a hacker's computer. Just because its an India store doesn't mean the hacker is Indian.
Some engadget reader sent the content of the file with a screenshot. Maybe a hacker's computer not necessarily the hacker's computer. Just to be clear.
Re: Microsoft Store hacked in India, passwords stored in plain text
#13So I've worked in an ASP.net environment and I generally hated it, but ... The overall framework had a lot of features and examples abounded ( http://msdn.microsoft.com/en-us/library/ff648341.aspx)[2005] . It's very difficult to imagine a company > the many ASP.net examples in order to store passwords in plaintext. It's astounding to see that Microsoft itself did so... Seems that it says that examples don't actually…
Re: Microsoft Store hacked in India, passwords stored in plain text
#14Re: Microsoft Store hacked in India, passwords stored in plain text
#15Can someone explain why the screenshot contained text that looks Chinese.
http://wpsauce.com/wp-content/uploads/2012/02/microsoftstore...
http://ps.s.blog.163.com/blog/static/89878892201211132353615...
Note from the blog page
> 不解释,撸过~
actually means "No comment, fap fap fap"
Re: Microsoft Store hacked in India, passwords stored in plain text
#16Microsoft fully deserves the blame here, for not asking basic questions. Besides, the rest of the code is likely to be smelly too if the entire team failed to notice the issue.
Re: Microsoft Store hacked in India, passwords stored in plain text
#17I love how the fields are prefixed with acronyms for the table name.
Curious, is there a good reason to do this ever?
Re: Microsoft Store hacked in India, passwords stored in plain text
#18I love how the fields are prefixed with acronyms for the table name.
Curious, is there a good reason to do this ever?
I don't do this usually but I have run into a couple of occasions where it would have helped out.
Re: Microsoft Store hacked in India, passwords stored in plain text
#19Re: Microsoft Store hacked in India, passwords stored in plain text
#20I think Microsoft needs to take a ton of heat for this one.
a) They outsource something running on a Microsoft domain, with the Microsoft logo, etc to an external entity, something customers wouldn't know about unless they read the ToU
b) That external entity wasn't held to even the most basic of security precautions - no MSFT online property would even be allowed to store passwords (that's the job for the LiveID guys) let alone do it in cleartext.
This is the sort of move for which people should get fired over.