Oh honey, buckle up because this is a MASTERCLASS in how to absolutely obliterate security for twenty years straight. Someone really looked at password reset codes and thought "you know what? Let's just use the current time and a random number under 10,000, hash it, and call it a day!" The predictability here is *chef's kiss* catastrophic. Since microtime() gives you the current timestamp and they're only adding a teeny tiny random number, an attacker could literally just... try a bunch of combinations around the current time. And then they're only taking 6 characters from the MD5 hash? That's like locking Fort Knox with a diary lock from Claire's. The fact that this code was PUBLICLY VISIBLE on GitHub for a DECADE while millions of users trusted their accounts to this digital wet paper bag of security is the kind of corporate negligence that should come with a free therapy session for every affected user. Someone's LinkedIn is about to get a lot quieter.
A Website With Millions Of Users Was Generating Their "Secret" Password Reset Codes Like This For Two Decades
6 hours ago
397,443 views
0 shares
security-memes, password-reset-memes, bad-code-memes, security-fail-memes, md5-memes | ProgrammerHumor.io
More Like This
For The Love Of God, Just Let Me Log In
1 year ago
468.4K views
0 shares
She Should Have Asked The Devs First
4 months ago
587.7K views
0 shares
TOPSKY Dual Motor Electric Standing Desk Frame, Height Adjustable Sit Stand Base for Home Office, Fits Table Tops up to 70.8 x 31.5 Inch, 225 lb Capacity (Black, Without Stand)
Affiliate
Standing Desks
TOPSKY
Monkey's Paw Marketing For Crowdstrike
1 year ago
370.2K views
0 shares
Copilot Autocompletes An API Key
1 year ago
617.0K views
0 shares
Loading more content...
AI
AWS
Agile
Algorithms
Android
Apple
Bash
C++