Hacker News new | ask | show | jobs
by pille 4478 days ago
He claims to have notified Criticker in 2010, and links to a post on their forum (username teario):

http://www.criticker.com/forum/viewtopic.php?f=8&t=2063#p188...

2 comments

From a quick glance at their forums, there are no posts about this (yet). It will be interesting to see how users feel about this.

It will also be interesting to see if the company makes any warning that the average user will understand (e.g. "don't reuse your Criticker password on other sites, especially email or financial, because your password here is not secret, at all").

Thanks for that, I skipped over that paragraph.
I don't think his post was blatant enough for the devs to pick up on it. Seems like the only guy that responded tl;dr'd it. He should have stated very clearly that this is a MAJOR security issue.
Agreed - He didn't even say that it was an issue at all. He seemed more concerned that the users are scoped to particular API keys and that he will lose his reviews.