4

So, I ran a test on one of the education websites I'm currently using (AT SCHOOL!!) To see how secure they are...... They sent me my password in plaintext FFS!

Comments
  • 1
    They sent you the password at the registration or because you reset the password?
  • 1
    @altermind I should clarify, I clicked the 'forgot password' button. No reset or anything, they just sent me my password in an email.
  • 1
    Just contact them and tell about the issue, explain why it is important to encrypt the user's sensitive informations
  • 1
    @altermind that's the plan. I was just surprised by how inept the website was.
  • 1
    Heh, that's nothing. My coworker actually changed his scores by SQL injection in university's databases. Twice.
Add Comment