3272
posted ago by Mike ago by Mike +3280 / -8

I just read on /r/the_donald about a new reader for this site that persists your authentication credentials.

While this person could have the best of intentions and is just trying to be helpful. Please understand this is a security concern for those who wish to maintain the integrity of your user credentials. As a 25 year software engineering professional with a background in security. If I was inclined to spoof your user account, I would build a kick ass app you could not resist.

Please, be patient. Only use readers or apps that this website has approved and verified safe.

Mods, it is perfectly acceptable to request source code and put these apps through a code review process to verify proper conditions are met. If you need help with identifying these potential issues issues feel free to reach out to me and I will provide a resume, work history and references.

Please, please, please refrain from authenticating to this site via a third party app.

Please support this message by pushing it to the top or have mods put out a sticky notification

*Edit: Fixed auto-correct spelling (protein tips =/= potential)

Comments (152)
sorted by:
You're viewing a single comment thread. View all comments, or full comment thread.
34
deleted 34 points ago +35 / -1
13
ThePlague 13 points ago +13 / -0

Nothing wrong with Trust but verify. Even IF there wasn't a political motivation, an attempt at a migration like this is ripe for spoofing and squatting, if for nothing else but the lulz. However, after the way the sub was treated on Reddit, and in the MSM in general, there's little doubt that there exists at least some bad actors who would love nothing more than taking this site down.