Skip to content

Comment on Yet Another Hot Startup Leaves A Gaping Security Hole In Its iPhone App

Comments

I don't know why this is so surprising, 99% of the websites and apps I see don't use SSL for login, even HN doesn't. It's good that this issue is getting more attention, but to specifically call out Instagram for it makes it seem like what they're doing isn't the industry norm.

Looking at the TC comments it seems like a lot of people are confused by the difference between sending your password in cleartext, and storing your password in cleartext, although I wouldn't be surprised if they're storing your tumblr and foursquare credentials in the clear.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.