Ok.......this is NOT supposed to be "political".
A "software security expert" was being interviewed about the "front end/sign up" on the ACA.
He had been asked by a relative to help getting signed up.
Basically they couldn't get very far but did "get somwhere".
He then did the "view page source" a term we all know, (however he did not use that term).
And found that "the password was being held in the browser".
The above is the best transcription that I can make.
A few sentences later he said....
"However, I filed a bug and it is now fixed".
Ok..................I knew about view page source years ago....
I am sure that any hacker knows about it.
And............yes........ what was left unsaid was that a "hacker" would have to go to break into your house, go to your computer open the browser and view source to get the password for ONLY your account...but...
The question I have for the various security experts that visit the forum is:
"Is this not something that ANY "programmer" who has a security expert working alongside would have taken care of first thing".
Again, this is not supposed to be "political"..........
It is just a question about the "expertise" of the people who were producing the website and also........the oversight by higher ups in the chain.
Just a question, nothing more.
woodsmoke
A "software security expert" was being interviewed about the "front end/sign up" on the ACA.
He had been asked by a relative to help getting signed up.
Basically they couldn't get very far but did "get somwhere".
He then did the "view page source" a term we all know, (however he did not use that term).
And found that "the password was being held in the browser".
The above is the best transcription that I can make.
A few sentences later he said....
"However, I filed a bug and it is now fixed".
Ok..................I knew about view page source years ago....
I am sure that any hacker knows about it.
And............yes........ what was left unsaid was that a "hacker" would have to go to break into your house, go to your computer open the browser and view source to get the password for ONLY your account...but...
The question I have for the various security experts that visit the forum is:
"Is this not something that ANY "programmer" who has a security expert working alongside would have taken care of first thing".
Again, this is not supposed to be "political"..........
It is just a question about the "expertise" of the people who were producing the website and also........the oversight by higher ups in the chain.
Just a question, nothing more.
woodsmoke
Comment