somabc Posted March 15, 2011 Posted March 15, 2011 I'm trying hard to think of a situation where this would actually be necessary? Welcome to our Login Page RETURNING CUSTOMERS, PLEASE NOTE THE FOLLOWING SECURITY CHANGE: YOUR USERNAME WILL NOW SERVE AS YOUR PASSWORD AND YOUR PASSWORD WILL NOW SERVE AS YOUR USERNAME The Caledonian-Record
elsiegee40 Posted March 15, 2011 Posted March 15, 2011 So which of the 100 users who had password as their password has the username that will let them login?!
Martin Posted March 16, 2011 Posted March 16, 2011 So they hold passwords as plain text? DOUBLE fail! mb
Chris_Jones Posted March 16, 2011 Posted March 16, 2011 And what about if 2 (or more) customers used the same password?
Flakes Posted March 16, 2011 Posted March 16, 2011 So they hold passwords as plain text? DOUBLE fail! mb they could convert entered text into MD5 using the built in PHP function then match that to the database, doesnt mean they hold em in plain text.
Hightower Posted March 16, 2011 Posted March 16, 2011 It's kind of morally wrong, like "your mother is now your father, and your father is now your mother"
sted Posted March 16, 2011 Posted March 16, 2011 when i worked at a bt callcentre their usernames and passswords were like that backwards my username was ascii jibberish and password was some variation of my name
SteveBentley Posted March 16, 2011 Posted March 16, 2011 That's gonna be good for people who use the same password for multiple sites, to now see it being entered in the username box in plain text rather than dots in the password box
joe90bass Posted March 16, 2011 Posted March 16, 2011 Speechless.......... Wonder what El Reg would make of it!?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now