By using this site, you agree to our Privacy Policy and our Terms of Use. Close

Forums - General - Storing passwords in plain text. Foursquare and Netflix doing it, too.

source

Foursquare and Netflix Apps Are Storing Your Passwords Unencrypted

Storing passwords in plaintext is a bad idea. You'd think that the smarties at Netflix and Foursquare would know better. But the Wall Street Journal reports their Android versions—and other apps—do no such thing. Not good.

According to security firm viaForensics, the the Netflix, Foursquare, and LinkedIn apps for Android are storing your passwords without a trace of encryption. Square's apps for both Android and iOS are vulnerable as well—albeit differently—revealing transaction and digital signature histories to prying hacker fingers.

Any responses, fellas? Foursquare, LinkedIn, and Netflix have all released mea clupas, saying they're "working on" fixes for the unencrypted vitals. Square, on the other hand, blames global credit card standards for the data their app holds. Keep that in mind next time you swipe your card through someone's phone. [WSJ]

Where the hell do these companies find their programmers?



Around the Network
Galaki said:

source

Foursquare and Netflix Apps Are Storing Your Passwords Unencrypted

Storing passwords in plaintext is a bad idea. You'd think that the smarties at Netflix and Foursquare would know better. But the Wall Street Journal reports their Android versions—and other apps—do no such thing. Not good.

According to security firm viaForensics, the the Netflix, Foursquare, and LinkedIn apps for Android are storing your passwords without a trace of encryption. Square's apps for both Android and iOS are vulnerable as well—albeit differently—revealing transaction and digital signature histories to prying hacker fingers.

Any responses, fellas? Foursquare, LinkedIn, and Netflix have all released mea clupas, saying they're "working on" fixes for the unencrypted vitals. Square, on the other hand, blames global credit card standards for the data their app holds. Keep that in mind next time you swipe your card through someone's phone. [WSJ]

Where the hell do these companies find their programmers?

It's not programmers fault. Programmers do what they receive in specification.

The ones to blame are software designers and ignorant managment.



PROUD MEMBER OF THE PSP RPG FAN CLUB

I wonder how quiet this thread will be.



Vetteman94 said:
I wonder how quiet this thread will be.

pretty quite... someone has to have access/steal your phone before he can hack it and then find the apps and the passwords...



 

Face the future.. Gamecenter ID: nikkom_nl (oh no he didn't!!) 

The problem is not in store the passwords in textfiles... the problem is store in textfiles without encryption... that's bad, really bad.



Around the Network
NiKKoM said:
Vetteman94 said:
I wonder how quiet this thread will be.

pretty quite... someone has to have access/steal your phone before he can hack it and then find the apps and the passwords...

So stuff that happens on a regular basis nowadays



ethomaz said:
The problem is not in store the passwords in textfiles... the problem is store in textfiles without encryption... that's bad, really bad.

Yeah thats the problem, but nowadays the level of encryption done is important to know too.



All hail the KING, Andrespetmonkey

You'd think a default security requirement would be encryption on passwords.



superchunk said:
You'd think a default security requirement would be encryption on passwords.


Yea. It should be common sense. Glad someone out there found this out. Companies need to be called out on this stuff and get it fixed



thranx said:
superchunk said:
You'd think a default security requirement would be encryption on passwords.

Yea. It should be common sense. Glad someone out there found this out. Companies need to be called out on this stuff and get it fixed

They probably invest about $9.99 into security.

Add LinkedIn and Square to the list of criminal negligence.