|
At least it has a password!
Last post 12-28-2012 4:14 AM by dhromed. 21 replies.
-
12-18-2012 8:22 AM
|
|
-
Evo


- Joined on 10-16-2006
- Posts 91
|
At least it has a password!
In my area, you can register at some foundation if you want to rent a home. Actually, I think it's the only way to rent a home in the public market, which is heaps cheaper than the private market.
The website (http://www.woonnet-haaglanden.nl) is a skilfully engineered flash-based website. Flash because, obviously, HTML can't do any of those things that one desires in a website. Who cares that you can't actually scroll without some ugly flash-based scrollbar, or that the site is slower than a snail running a marathon? Anyways, that's no the point here...
When you register, you get a "pass number". Using this passnumber and date of birth you can log in, except that you can also set a password. At least, I guess it was optional because it pops up with a message saying "You set a password, please enter it". But then again, everybody may be forced to set a password and be prompted with the same dialog, so I'm not completely sure if the password was mandatory or not. However, after entering my password, it went to the logged in page. Quickly. Too quickly. The rest of the site was way too slow, but this felt just a tad to fast.
You can probably guess the story from here: I launched a packet sniffer, re-entered my pass number and my date of birth, and quit the process there. Upon looking through the packet that the server it replied with, I could see my phone numbers, my address, my bank information... And my password. In clear text. Without ever entering it.
At least it supports a password, right?
|
|
-
-
TGV


- Joined on 10-09-2005
- Posts 563
|
Re: At least it has a password!
It's totally safe, because a hacker will expect that you send your details to the server, but no hacker will expect it to be the other way around!
|
|
-
-
Ben L.


- Joined on 12-22-2010
- HELP I'M TRAPPED IN A COMMUNITY SERVER FACTORY
- Posts 1,874
|
Re: At least it has a password!
357. The client can validate login information.
|
|
-
-
Ragnax


- Joined on 02-01-2007
- Posts 231
|
Re: At least it has a password!
This is a violation of Dutch privacy laws regarding the treatment of personally identifiable information. Chapter 2, article 13 of the Dutch "Wet bescherming persoonsgegevens" states that the responsible party (i.e. woonnet haaglanden) needs to ensure that adequate technical measures have been taken to protect your personally identifiable information, preventing it from being leaked to third parties and shielding it from unlawful use. Ensuring communication takes place over an encrypted connection is the
most trivial of verifications. This could well be categorized as willful
ignorance, in which case Chapter 10, paragraph 3, article 75, 2nd member would make it a criminal offence.
Have you reported this to the proper authorities yet? The "College bescherming persoonsgegevens" would have a field day with these clowns...
|
|
-
-
dtech


- Joined on 11-13-2007
- Utrecht, Netherlands
- Posts 808
|
Re: At least it has a password!
Well, at least they're replacing it in a few days, according to the large red header with warning sings in it...
(trans: You can reply to our housing selection untill wednesday 19 december 12 AM. Our new website goes live on 20 december, but there will not be any offers because of the holidays. See also the message at Current)
|
|
-
-
Gurth


- Joined on 01-24-2012
- Posts 143
|
Re: At least it has a password!
They're replacing "the website", which doesn't necessarily mean also the backend that deals with user authentication or anything else of only minor importance :)
|
|
-
-
-
dhromed


- Joined on 04-13-2005
- Dutchland
- Posts 10,305
|
Re: At least it has a password!
Gurth:They're replacing "the website", which doesn't necessarily mean also the backend that deals with user authentication or anything else of only minor importance :) In theory, yes. In reality, it's often Nuke the old, Make new.
 boomzilla: I think the obvious answer is for everyone to just stop programming.
|
|
-
-
keigezellig


- Joined on 01-08-2008
- Venlo, The Netherlands
- Posts 38
|
Re: At least it has a password!
Or you could (besides reporting it to the authorities) contact a journalist of a newspaper to do a story about this. These days a lot of security WTFs (e.g. Diginotar) pop up in The Netherlands and in the newspapers
|
|
-
-
LoremIpsumDolorSitAmet


- Joined on 10-15-2012
- London
- Posts 34
|
Re: At least it has a password!
Giving the story away would be a bad idea, because you would be exposing the security exploit to everyone and allowing yourself (and everyone else) to be hacked. Of course, reporting it to the authorities would reveal it too, but to a much smaller and, hopefully, more trusted set of individuals.
|
|
-
-
Evo


- Joined on 10-16-2006
- Posts 91
|
Re: At least it has a password!
LoremIpsumDolorSitAmet:Giving the story away would be a bad idea, because you would be exposing the security exploit to everyone and allowing yourself (and everyone else) to be hacked. Of course, reporting it to the authorities would reveal it too, but to a much smaller and, hopefully, more trusted set of individuals.
I guess it's a bit too late not to release it ;-). Anyway, they simply use your pass number and date of birth as identification. I actually unset my password: the password is, indeed, optional. So I just hope there's no way to get my pass number, given my name...
Let's see how their site changes tomorrow, and if it's not fixed yet, I'll contact someone about this.
|
|
-
-
dhromed


- Joined on 04-13-2005
- Dutchland
- Posts 10,305
|
Re: At least it has a password!
Basically, if you steal my wallet, you can hypothetically sign me up for a real shitty apartment*. *) not that those apartments are all shitty. They're fine. Just that some of them will probably be shitty, as with every large collection of things.
 boomzilla: I think the obvious answer is for everyone to just stop programming.
|
|
-
-
-
LoremIpsumDolorSitAmet


- Joined on 10-15-2012
- London
- Posts 34
|
Re: At least it has a password!
Hurrah! New website today. Looks like the password is definitely mandatory now.
|
|
-
-
dhromed


- Joined on 04-13-2005
- Dutchland
- Posts 10,305
|
Re: At least it has a password!
LoremIpsumDolorSitAmet:Hurrah! New website today. Looks like the password is definitely mandatory now.
WELP
Your password may have a maximum of 10 characters. TOLD YOU SO TOLD YOU SO
 boomzilla: I think the obvious answer is for everyone to just stop programming.
|
|
-
-
ekolis


- Joined on 01-09-2008
- Cincinnati, OH, USA
- Posts 597
|
Re: At least it has a password!
What happens if you have a twin sibling? Or someone on the other side of the country just happens to have the same birthday as you? Even in a smaller country like the Netherlands, that's bound to happen, right?
I'm Spark Mandrill, and I'll... hey... can I... what, it BOUNCES?... 'kay, I'm splodin' now.
|
|
-
-
dhromed


- Joined on 04-13-2005
- Dutchland
- Posts 10,305
|
Re: At least it has a password!
ekolis:What happens if you have a twin sibling? Well nothing, because you both get different user numbers.
 boomzilla: I think the obvious answer is for everyone to just stop programming.
|
|
-
-
ekolis


- Joined on 01-09-2008
- Cincinnati, OH, USA
- Posts 597
|
Re: At least it has a password!
dhromed: ekolis:What happens if you have a twin sibling? Well nothing, because you both get different user numbers.
I see nothing about "user numbers" - wouldn't you get the same "pass number", which apparently serves as a username?
I'm Spark Mandrill, and I'll... hey... can I... what, it BOUNCES?... 'kay, I'm splodin' now.
|
|
-
-
-
ekolis


- Joined on 01-09-2008
- Cincinnati, OH, USA
- Posts 597
|
Re: At least it has a password!
Could have sworn that it was based on your birthdate or something?
I'm Spark Mandrill, and I'll... hey... can I... what, it BOUNCES?... 'kay, I'm splodin' now.
|
|
-
-
-
dhromed


- Joined on 04-13-2005
- Dutchland
- Posts 10,305
|
Re: At least it has a password!
ekolis:Could have sworn that it was based on your birthdate or something? Ah, that is theoretically possible, even if it is crazy stupid. But I guess it's just as stupid as a 100% flash site so no surprises there?
 boomzilla: I think the obvious answer is for everyone to just stop programming.
|
|
Page 1 of 1 (22 items)
|
|
|