Queen crest Queenzone

Security Risk: Your passwords are stored on plain text

4 posts
Thread

Posts in chronological order

· Member since
I am a Programmer and a Queen fan (not one of these reddit guys or BoRap movie guys)..

I've been on QZ for a bit now and discovered that your passwords are stored on plain text.
Most websites nowadays hash your passwords before storing them, this is to ensure that even if a hacker breaks into the website, all that the hacker can get are 1 way mathemtical calculated strings that can not be reversed (Well it's complicated but there are cases where it can be).

I did not hack into QZ, the way I tried it is by simply attempting to reset my password, and I got my current password to my e-mail (remember, a website owner can not decrypt the hash even if they want), after a bit more research I found that you can view it your profile info too.


I strongly encourage you not to use your QZ password in any other websites.


I am sorry if I went too tecnical, and yes I know that this forum is well.. not the state of the art but I am just here to express a concern about QZ.
· Member since
Thanks for the heads- up!
· Member since
^Yes, thanks for telling us.
· Member since
Wow, good to know.