Account passwords appear to be insecure (not encrypted)
|
Jun 4, 2008
|
I noticed that TeamSnap account notifications include passwords in clear text. This implies that passwords are not as encrypted on TeamSnap servers, and, therefore, systems can be compromised through unintentional or malicious acts. Can TeamSnap confirm whether passwords are stored as encrypted, and if not, when that might be addressed? |
|
Jun 23, 2008
|
This is being addressed right now and should be changed this week. Thanks! Andrew @ TeamSnap |
|
Jun 30, 2008
|
Thanks, Andrew. There are other security issues that we’ve noticed since, and I’ve cited some below. The crux of the issue is that TeamSnap allows entry and storage of personal information, so all access and storage must be encrypted.
|
|
Jul 22, 2008
|
I can tell you that we will be implementing some, but not all, of these suggestions when we launch the paid service. Thanks :) Andrew |
To post a reply, just create an account or sign in (if you already have one).