SECURITY FLAW!

Moderator: Unholy

Re: SECURITY FLAW!

Postby AndyPoms » Fri Mar 22, 2013 6:51 am

Did you see that the fields on Signup are Username, Nickname, Password, Confirm Password? Your Nickname overrides your username for display.
Image
Waze Champ & Forum Moderator
USA Country Manager
Senior Area Manager: State of Connecticut
Wiki: Editing | Best Practices | FAQ
AndyPoms
Waze Global Champs
Waze Global Champs
 
Posts: 6539
Joined: Tue Dec 27, 2011 1:34 pm
Location: Hartford, CT
Has thanked: 112 times
Been thanked: 1101 times

Re: SECURITY FLAW!

Postby Daknife » Fri Mar 22, 2013 4:57 am

Please post device (make and model), OS (make and ver) and password (j/k on that one) This has not been produced before, and as a single instance is suspect.
Image
AM in Utah; CM USA
Utah Forum: Utah Forum
Samsung Galaxy S4 running 4.4 KitKat on Sprint
Daknife
Waze Mentor
Waze Mentor
 
Posts: 1677
Joined: Sat Dec 24, 2011 11:03 pm
Location: Riverdale, Utah
Has thanked: 452 times
Been thanked: 225 times

Re: SECURITY FLAW!

Postby porubcan » Fri Mar 22, 2013 8:07 am

Fields when registering are:
Username
Password
Nickname (not repeat password). So you put your password as your nickname. .

Just change Nickname and your password will not be published anymore

Sent from my HTC One X using Tapatalk 2
Image Image Image
SK Country Coordinator, SK Country Manager, Global Champ, Android Beta Tester
Waze 3.9.4.0 on HTC One, Android 5.0 @ white Škoda Octavia RS Combi
porubcan
Waze Global Champs
Waze Global Champs
 
Posts: 4504
Joined: Mon Jan 02, 2012 9:13 am
Location: Slovakia
Has thanked: 445 times
Been thanked: 1165 times

SECURITY FLAW!

Postby ryanwkan » Fri Mar 22, 2013 4:52 am

As a fellow developer, I am deeply concerned about the security of your app.

I signed up today, picked my username and password and guess what? My PUBLIC username defaulted to my PASSWORD!!!

How is it that you even have my password? Isn't it supposed to be encrypted?

Concerned
ryanwkan
 
Posts: 3
Joined: Fri Mar 22, 2013 4:34 am
Has thanked: 0 time
Been thanked: 0 time

Re: SECURITY FLAW!

Postby ryanwkan » Fri Mar 22, 2013 6:37 am

iPhone 5

Ios 6.1.3
ryanwkan
 
Posts: 3
Joined: Fri Mar 22, 2013 4:34 am
Has thanked: 0 time
Been thanked: 0 time

Re: SECURITY FLAW!

Postby ryanwkan » Fri Mar 22, 2013 6:55 am

I only remember keying in password twice
ryanwkan
 
Posts: 3
Joined: Fri Mar 22, 2013 4:34 am
Has thanked: 0 time
Been thanked: 0 time


Return to Website, Community, General

Who is online

Users browsing this forum: No registered users