Follow

do you ever accidentally expose the password hash of your users in public, unauthenticated APIs

poor Olle

· · Web · 2 · 0 · 3

i've notified them of this which means that either

a) they will thank me and fix it

or

b) they will threaten to call the cops and completely ignore the problem

Olle just responded from the helpdesk with option A :dragnuwu:

@Dee i usually just email the Swedish CERT and tell them to deal with it lol

@Gulfie less of an issue here since it's a business email and kinda public, but yeah

Sign in to participate in the conversation
Fuzzy Systems Masto

Instance run by a non-profit association, with a mission to encourage an open internet, welcoming to everyone.