Larion Studios forum stores your passwords in unhashed plaintext. Don’t use a password there that you’ve used anywhere else.

You are viewing a single thread.
View all comments View context
20 points

Stored in memory is still stored.

Given what I know about how computers accept user input, I am fascinated to hear what the alternative is.

permalink
report
parent
reply
-33 points
*

You have the text input feed directly into the encryption layer without an intermediary variable. The plaintext data should never be passable to an accessible variable which it must be to send the plaintext password in the email because it’s not an asynchronous process.

I’m surprised so many people are getting hung up on basic infosec.

permalink
report
parent
reply
11 points

Are you suggesting to do all this on the frontend before it goes to the backend?

permalink
report
parent
reply
-19 points
*

The front end to backend traffic should be encrypted, hashing occurs on the backend. The backend should never have access to a variable with a plaintext password.

I’m going to have to stop replying because I don’t have the time to run every individual through infosec 101.

permalink
report
parent
reply
4 points
*

If they can send you, your own password in plain text. That’s already bad enough. Just not good practise.

permalink
report
parent
reply

Games

!games@lemmy.world

Create post

Welcome to the largest gaming community on Lemmy! Discussion for all kinds of games. Video games, tabletop games, card games etc.

Weekly Threads:

What Are You Playing?

The Weekly Discussion Topic

Rules:

  1. Submissions have to be related to games

  2. No bigotry or harassment, be civil

  3. No excessive self-promotion

  4. Stay on-topic; no memes, funny videos, giveaways, reposts, or low-effort posts

  5. Mark Spoilers and NSFW

  6. No linking to piracy

More information about the community rules can be found here.

Community stats

  • 9K

    Monthly active users

  • 4.4K

    Posts

  • 91K

    Comments