The company behind the Signal clone used by at least one Trump administration official was breached earlier this month. The hacker says they got in thanks to a basic misconfiguration.

  • Raltoid@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 days ago

    Client side md5 password hashing, JSP, having public facing links to dump the heap due to default configuration…

    Either this was made by someone who took a programming course twenty years ago and haven’t touched it since. Or it was intentionally made to be insecure.