Live data from Hacker News

Hacking Grindr Accounts with Copy and Paste

troyhunt.com

201–202 of 202 posts

Re: Hacking Grindr Accounts with Copy and Paste

#201
post #117

Earlier quoted context omitted.

So were they denying clearances to openly gay people back in the old days? Because there wouldn’t be potential for blackmail in that case. Sorry I can’t tell what you’re saying changed about the policies.

Thirty years ago George Bush Senior was president, Reagan has recently left office, and the United States government was handling HIV poorly and intentionally so. Sodomy laws were still on the books - can you keep a clearance while openly breaking the law every time you and your partner sleep together?

I don't know, that's why I asked since the original commenter seems to know, but his original comment doesn't really answer it as it basically says "they used to deny clearances to secretly gay people, and today they grant them to openly gay people".

Re: Hacking Grindr Accounts with Copy and Paste

#202

Earlier quoted context omitted.

Could you explain why that's bad for someone who knows nothing about security? Where should the password reset token be?

The token should only be accessible to the user requesting the password reset, meaning that it would be sent via email (this is the standard password reset flow). The flaw here is that anyone, even if they did not control the email of the user, could reset the password, because the reset token was returned in the browser, where anyone could see it. Essentially, just by knowing someone's email (not having control over…

You did a really great job breaking that down! Thank you!
Post reply on HN