5 ms·
Microsoft Store hacked in India, passwords stored in plain text
- sathyabhat 15y agoPrevious submission. http://news.ycombinator.com/item?id=3582393 http://news.ycombinator.com/item?id=3582393
- unhappyhippie 15y agoCan someone explain why the screenshot contained text that looks Chinese.
- zalthor 15y agoI think engadget just blurred out the passwords there.
- latch 15y agoNo, if you look at the characters in the UI. Still, clearly the answer is that's a hacker's computer. Just because its an India store doesn't mean the hacker is Indian.
- Jagat 15y agoHere is the image that shows the passwords (email IDs are still hidden though). http://img7.ph.126.net/wWJQXBUb5HzfZKPphMH9iA==/2882866711487786527.jpg http://img7.ph.126.net/wWJQXBUb5HzfZKPphMH9iA==/288286671148... I'm pretty impressed by their choice of passwords, except for one Aseem Bansal who has aseembansal as his password. And here's the hacker's blogpost that has some screenshots http://ps.s.blog.163.com/blog/static/89878892201211132353615/ http://ps.s.blog.163.com/blog/static/89878892201211132353615...
- est 15y agoaccording to the hacked page, it's obviously a Chinese Hacker http://wpsauce.com/wp-content/uploads/2012/02/microsoftstoreindiaevilhacked.jpg http://wpsauce.com/wp-content/uploads/2012/02/microsoftstore... http://ps.s.blog.163.com/ http://ps.s.blog.163.com/ http://ps.s.blog.163.com/blog/static/89878892201211132353615/ http://ps.s.blog.163.com/blog/static/89878892201211132353615... Note from the blog page > 不解释,撸过~ actually means "No comment, fap fap fap"
- deleted 15y ago[deleted]
- kaka2 15y agogot the origin links_source 哈哈。葫擼娃
- latch 15y agoI love how the fields are prefixed with acronyms for the table name.
- drivebyacct2 15y agoCurious, is there a good reason to do this ever?
- aidos 15y agoI guess you could say that then you never have to qualify the column name in the query (as they're unique across the system). It's a pretty crummy reason to do it though. More likely it's just that someone decided that was how they were going to do it one day and it stuck. I worked on a system where all tables were prefixed with "tbl_" - even when they were often views and not tables at all....
- RyanMcGreal 15y agoGotta love cargo cult Hungarian notation.
- rbanffy 15y agoJust to be clear, not all Hungarians endorse this notation ;-)
- haberman 15y agoThey were probably using a C compiler from the 70s that puts all struct members in a global namespace.
- burgerbrain 15y agoThe effort it would require to do something that absurd is astonishing.
- 15y ago
- yeahboats 15y agoThe store isn't actually run by microsoft, but rather Quasar Media. It tarnishes Microsoft's name, but it isn't their fault. http://www.theverge.com/2012/2/12/2793459/microsoft-store-india-hacked-username-password-leak http://www.theverge.com/2012/2/12/2793459/microsoft-store-in...
- CoffeeDregs 15y agoWas it the Microsoft store or not? If it was an MS store, then it's their fault. The store was branded with the MS brand in order to convey to consumers that the store could be trusted. That Microsoft contracted hosting/development out to a crappy firm is Microsoft's fault not the consumer-who-trusted-their-brand's fault. Users trusted that an Microsoft-branded domain would be kind. Fail.
- CoffeeDregs 15y agoSo I've worked in an ASP.net environment and I generally hated it, but ... The overall framework had a lot of features and examples abounded (http://msdn.microsoft.com/en-us/library/ff648341.aspx)[2005] http://msdn.microsoft.com/en-us/library/ff648341.aspx)[2005]. It's very difficult to imagine a company <<skirting around>> the many ASP.net examples in order to store passwords in plaintext. It's astounding to see that Microsoft itself did so... Seems that it says that examples don't actually abound or that the system is so complex that not even Microsoft could understand it. More likely, Microsoft hired a low-cost contractor to build/manage their Indian site and suffered. Another sign that MS has lost touch. EDIT: another commenter writes "The store isn't actually run by microsoft, but rather Quasar Media.", so Microsoft outsourced their site...
- tomfakes 15y agoA long time ago (10+ years), Microsoft cleaned up all of their sample code for security purposes to avoid people cut and pasting insecure code to stop exactly this type of boneheadedness.
- jeswin 15y agoWhenever you outsource make sure you watch the code very, very carefully. At least 90% of the people I meet (at least here in Bangalore) would store passwords in clear text and not know why this is a bad thing. Microsoft fully deserves the blame here, for not asking basic questions. Besides, the rest of the code is likely to be smelly too if the entire team failed to notice the issue.
- sceptre 15y agoso you went around asking people how they store passwords, did you? Load of crap!!!
- richardlblair 15y agoMicrosoft definitely need to take the burn on this one. You don't even need to look at the code to find out the passwords are stored in plain text. A quick tour through the database during testing would tell you everything you need to know here. This is nothing more than laziness and ignorance.
- sriramk 15y agoDisclaimer: I used to work for Microsoft I think Microsoft needs to take a ton of heat for this one. a) They outsource something running on a Microsoft domain, with the Microsoft logo, etc to an external entity, something customers wouldn't know about unless they read the ToU b) That external entity wasn't held to even the most basic of security precautions - no MSFT online property would even be allowed to store passwords (that's the job for the LiveID guys) let alone do it in cleartext. This is the sort of move for which people should get fired over.
- teyc 15y agoThis reminds me of the spate of hacks on Sony's sites. I wonder how many more MS sites are operated by third parties, and exactly how vulnerable are our personal information? Let the heads roll.
- illumen 15y agoDoesn't ycombinator still store passwords in plain text? Or has that been fixed now?
- eddie_the_head 15y agoThe version of news.arc last shipped from arclanguage.org hashes the passwords (I'm not sure what exactly it uses), and that's very old. pg and rtm might've changed it since. I highly doubt that HN ever stored passwords plain text, especially considering who rtm is.
- spatulon 15y agoHN uses bcrypt: http://news.ycombinator.com/item?id=3099563 http://news.ycombinator.com/item?id=3099563
- Jagat 15y agoGuess what, they seem to be managing some of Nokia's and Panasonic's resources as well. Off you go Quasar Media, you're doomed. Here's the actual blogpost from the one who claims to be the hacker http://ps.s.blog.163.com/blog/static/89878892201211132353615/ http://ps.s.blog.163.com/blog/static/89878892201211132353615...
- Jagat 15y agoIncorrect report, there was no image with a Guy Fawkes mask. This is the actual image that had appeared on the site http://i.imgur.com/vcLal.png http://i.imgur.com/vcLal.png Some self-promoting guy seems to have sent Endgadget that screenshot.
- buyx 15y agoNot suprising, a few years ago, I forgot my password for the Ted Ed South Africa website. I phoned in to reset, and had my password read back to me over the phone.