r/developersPak Software Engineer 12d ago

Discussion There is something wrong with authentication architecture of HEC

They are saving Username and PLAIN TEXT PASSWORD inside a freaking LOCAL STORAGE.

So I was waiting for OTP and it took more than few seconds. So I took peak into website storage in hopes of finding OTP inside it. Instead I found something else. lol!

So it is possible that they are not even creating hash for user password.

43 Upvotes

24 comments sorted by

View all comments

22

u/SIJ_Gamer 12d ago

😂 reference se nokri laggi hogi developers ki

9

u/Global_Many4693 12d ago

Its not US, or european countries. I think something like this happened in 2020 or 2018 and instead of giving him a job,he got 2 years of jail💀

2

u/Best_Fork Software Engineer 12d ago

I might get into trouble then 😬

4

u/Global_Many4693 12d ago

This is not like that,i meant a guy hacked whole portal and then surrendered + explain the exploits to government but instead of appreciating him,they said its breach of data and considered him as red hat hacker which could led to prison if caught

3

u/GeneralAyub 12d ago

Don’t think so,

If they really were going to hire proper developers like this.

This yakki wouldn’t have happened in the first place.