DEV Community

Discussion on: What are the worst security practices you've ever witnessed?

Collapse
 
arximughal profile image
Muhammad Arslan Aslam

I went for an interview at a Startup so I thought it would be better to checkout their application beforehand. Their password reset API was taking two parameters, email address of the account and the new password!!!

It's been three years since I've informed them of this, and they still haven't changed that!