Hacker News new | ask | show | jobs
by zoowar 5612 days ago
WARNING: They say "Don't worry, we don't store your Netflix credentials."

Instead, they send them in plain text over the network!

From wireshark: email=hello&password=hackers&Login=Get+my+Netflix+Instant+Q

PS: no ssl support (https://www.qpicker.com/)

2 comments

Hi zoowar, thank you for catching the no-ssl issue. We are working with our host to have that fixed today. I'll update everyone when ssl is setup because we do want to make the site secure.
Also, your splash page is confusing. An 'authenticate with netflix' button would be better. If you need users to 'sign up' with your site, make that a seperate and distinct operation.
Just wanted to update that we finally established SSL support. Thank you again for the feedback zoowar!