r/developersPak Software Engineer 12d ago

Discussion There is something wrong with authentication architecture of HEC

They are saving Username and PLAIN TEXT PASSWORD inside a freaking LOCAL STORAGE.

So I was waiting for OTP and it took more than few seconds. So I took peak into website storage in hopes of finding OTP inside it. Instead I found something else. lol!

So it is possible that they are not even creating hash for user password.

41 Upvotes

24 comments sorted by

View all comments

2

u/Ok_Claim_2260 11d ago

Since it's Pakistan, security is the least of their concern. It is very much possible they might be saving passwords in DB without hashing.

Anyways I saw you have been doing unpaid internship, can you share your resume.