Hacker News new | ask | show | jobs
by ancarda 4478 days ago
>I don't see how this is an issue

Stealing 2853 user's passwords, which are stored in plaintext, sent over HTTP isn't an issue? This wasn't an SQL injection, the API gives it away.