Live data from Hacker News

Bookmyshow.com Saves User Passwords in Plain Text

blog.archit.in

1–5 of 5 posts

Re: Bookmyshow.com Saves User Passwords in Plain Text

#2
They could have encrypted your password and decrypted it for that email. Still poor practices but there's nothing here to indicate what your title states.

The bottom of your article also suggests people use MD5 and salts, so clearly you aren't in a position to be criticizing anyone's password policy :)

Re: Bookmyshow.com Saves User Passwords in Plain Text

#3

They could have encrypted your password and decrypted it for that email. Still poor practices but there's nothing here to indicate what your title states. The bottom of your article also suggests people use MD5 and salts, so clearly you aren't in a position to be criticizing anyone's password policy :)

The privacy policy states the password is sent by one way encryption. That suggests it shouldnt be (easily) decryptable.

Regarding MD5/salts, the author says "for starters" and "at least" and directs the suggestion specifically to the owners of the website. To say he is "suggesting people use MD5 and salts" isnt very accurate.

Re: Bookmyshow.com Saves User Passwords in Plain Text

#4

They could have encrypted your password and decrypted it for that email. Still poor practices but there's nothing here to indicate what your title states. The bottom of your article also suggests people use MD5 and salts, so clearly you aren't in a position to be criticizing anyone's password policy :)

[deleted]

Re: Bookmyshow.com Saves User Passwords in Plain Text

#5

They could have encrypted your password and decrypted it for that email. Still poor practices but there's nothing here to indicate what your title states. The bottom of your article also suggests people use MD5 and salts, so clearly you aren't in a position to be criticizing anyone's password policy :)

Hey timaelliott,

As benjaminsull mentioned, I wrote "for starters" and "at least!" ;)