Skip to content

Comment on Tuts+ accounts hacked - User passwords stored in CLEARTEXTparent

Comments

Clearly, this was a disaster waiting to happen. Not that it would ever happen, but if websites were required to disclose how sensitive information was stored, I'd guess this sort of intrusion would be far less common, since no one would use a site that left passwords unencrypted/salted/hashed. Tuts+ is a HUGE service... 660 on Alexa today. I am beyond frustrated.

Makes a big case for OAuth in my mind.

I wish you were right, but check out the comments on the original article. Plenty of people whose response is "these things happen, good luck guys"

Plenty of developers have no fuckin clue about basic security, so why would users of a tutorial site?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.