Now I Have a Blog TooNow I Have a Blog Too Christopher Finke is a software engineer at Mahalo. He is available for birthday parties and bar mitzvahs.

Pownce has a big security problem

Kevin Rose's latest project, Pownce, has a glaring security problem on its front page. The JavaScript that Pownce uses in its login form can reveal your password in plain text on the screen. Here are the steps to reproduce the problem in Firefox:

  1. Login to Pownce via http://www.pownce.com/. Allow Firefox to save your login information for next time, and then log out.

    Pownce

  2. Navigate to http://www.pownce.com/ and type the first part of your username in the "Enter username..." box. Firefox will supply all of the matching usernames it remembers for this site. (So far, so good.)

    Using Firefox

  3. Select your username and press return to have the browser autofill the rest of your information. Oh look, there's your Pownce password in plain view! I hope no one in the room was watching you login...

    Hey look, it

The method that Pownce is using to show the "Enter password..." prompt in the password field is the reason for this malfunction; browsers force all text in password fields to be hidden with asterisks, so if you want to show normal text in a password field like Pownce has chosen to, you have to do so in a non-standard way.

This bug affects Firefox and Netscape users who have JavaScript enabled, but it doesn't affect Safari users.

2 Responses to “Pownce has a big security problem”

  1. Descubierto el Primer Fallo de Seguridad de Pownce » Marlex Systems Says:

    [...] Más Información | Now I have a Blog too [...]

  2. -- wathefak Says:

    [...] Pownce has security problems « WOW! The real transformer! | [...]

Leave a Reply