Post
Topic
Board Project Development
Re: Bitcoin Search Engine
by
Lemming
on 30/05/2013, 23:40:37 UTC
This is a very neat idea, I like it.

The site is clearly still in development, that's quite understandable and I don't have a problem with that. But when I, after creating an account, went to the "Account Details" page, my password was displayed. This is an indication of very poor security. A website should never store users' passwords, they should only store a (salted) hash. Here is a good explanation: http://crackstation.net/hashing-security.htm