So I recently had my account blocked until I changed my password for a more secure one, and sure, I did
But as I was doing it, I saw the "show password" button, which once pressed indeed showed the password I had set previously, and ...
WHAT THE HELL ????!!!!
Password for F95 are NOT encrypted in the database ?
Anyone with database access has the password of EVERYONE on the website ?
Password encryption on account creation has been a web standard for over 20 years, it is unthinkable that a community of 8,679,949 accounts (at the time of this message) would not implement such a basic security feature
Please patch this as soon as possible, because making people change their passwords is pointless if EVERY password can be accessed at once by phishing one admin
But as I was doing it, I saw the "show password" button, which once pressed indeed showed the password I had set previously, and ...
WHAT THE HELL ????!!!!
Password for F95 are NOT encrypted in the database ?
Anyone with database access has the password of EVERYONE on the website ?
Password encryption on account creation has been a web standard for over 20 years, it is unthinkable that a community of 8,679,949 accounts (at the time of this message) would not implement such a basic security feature
Please patch this as soon as possible, because making people change their passwords is pointless if EVERY password can be accessed at once by phishing one admin