Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

More accurate / precise headline: TechCrunch Startup Battlefield Australia site stores user passwords in plaintext

At the bottom it says "Powered by Trackiva" which looks to be a splash page service.

> Trackiva is the platform that powers the famous TechCrunch Battlefield application selection process.

So really it sounds like this splash page service, which looks to be relatively unknown in Google is insecure, making (at least) some of the OWASP Top 10 vulnerabilities.

Apparently the app is made by this company Fardini Media (https://www.fardinimedia.com/). Hopefully they'll find this thread from a Google Alert or something and fix it.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: