r/mildlyinfuriating • • Aug 29 '26

Ruined by Technology Lenstore displays my password and email on the address bar

Post image

Was trying to order some lens and I noticed my password on the address bar. I emailed them and let them know though.

18.0k Upvotes

600 comments sorted by

3.0k

u/Zippyversion1 Aug 29 '26

I had this once pre COVID. The irony being that it was a website with online safety resources for primary school teachers. I emailed and they sorted it immediately, but it makes you wonder...

889

u/pqu Aug 29 '26

As a high school student I got given a staff account on their online math platform because I was tutoring someone. On the admin page it had every single student’s username and password in plaintext, which was the same one as our windows login and email.

Ironically the kid I was tutoring was the son of the head of IT.

271

u/eladts Aug 29 '26

Thanks god the head of IT weren't tutoring their own kid.

152

u/Hazelberry Aug 29 '26

My high school set everyone's passwords as our last name + birthday. Our school district's IT was such an absolute joke that I accidentally got access to the entire school's personal records when I was just poking around the system files in the computer lab.

142

u/Ready-Delay3918 Aug 29 '26

In the 90s I changed everyone else grades except my own thinking it was different than changing only my grade and nobody else's.

Yeah they stil caught my dumb 8th grade ass.

A few years later in highschool.... Again...wide open system. I played it differently this time. Kid who was a total dick in my highschool. Like me, he was barely a B student but a real push random kids into the locker type guy. I ended up being late to class because he parked in my parking space. (On campus parking was preregistered and paid for). Told the office and they didn't care. Saturday Detention.

So I gave that fucker straight As.

He was in Saturday Detention with me for changing his grade. Saturday detention sucked with him there. Goddammit I thought I was so clever.

.....Fuck this hacker shit.

40

u/Mirality Aug 29 '26

In the 90s at my school you could get admin access on the network by just Ctrl-C at the login prompt. Don't ask me how I know.

14

u/amano32 Aug 30 '26

I had accidentally accessed my school's exam phpmyadmin database TWICE during high school. Ended up secretly ballooning up certain students grades using it. The dashboard page was not firewalled nor set with password.

→ More replies (5)

14

u/Confused_Rat600 Aug 29 '26

My districts IT department is such a joke that many network ports are on the Admin VLAN and the Town and School IT dept are connected in some way so then you have access to much, much more.

10

u/BluelDev Aug 29 '26

My district is the worst lol, from being able to bypass a firewall with command prompt on their laptops to them having 500+ users signed into a single laptop in less than a year resulting in 500mb of storage left, it's a joke bro

→ More replies (1)
→ More replies (6)

22

u/eremeya Aug 29 '26

I applied to a decent university I China a few years ago and decided not to go after noticing my username and password in the URL.

8

u/rodimustso Aug 29 '26

Thats a security audit waiting to fail. When you write a website backend/frontend there is nothing even remotely close to "why" you would even have login creds in a url.

7

u/JakSandrow Aug 29 '26

if: login_details_displayed;

dont;

else:

do;

6

u/[deleted] Aug 29 '26

[deleted]

→ More replies (1)

7

u/kingdead42 Aug 29 '26

They probably changed it so it's in plain text in your GET request instead of the URL...

3.5k

u/el_condor_nm Aug 29 '26

I once did a security analysis of a website with a 2,000 character URL string which included the database admin account and password in plain text. The client accused me of trying to blame the previous developer. I'm like, yeeeeah, he's the one who did it. The database they used was really big and it would have been trivial to set up an injection attack and add DROP DATABASE. C'ya!

1.6k

u/Effective_Repeat9967 Aug 29 '26

The client accused me of trying to blame the previous developer.

Isn't that the whole point of independent audits? To find out if the dev was an idiot or intentionally slacked off.

380

u/gunsandcupcakes Aug 29 '26

some people just want to be proven right more than anything else

62

u/Nevermind04 Aug 29 '26 edited Aug 29 '26

I was given a "promotion" to auditor in a previous job and without exaggeration 80% of the time, some manager would respond to the audit with "it's deeply unprofessional for you to point fingers." No, you pearl-clutching motherfucker - that's literally my job description. After about 5 months I told my boss I was either accepting my old job back with my current pay or I was walking out the door. I got my old job back.

I stayed there for several more years and no auditor they hired for that role made it past their 6 month probationary period. Eventually they gave up hiring for that role and just hired an external firm of soulless ghouls which is what they really should have done in the first place.

93

u/mrbiggbrain Aug 29 '26

No.

The point is to have an outside pair of eyes review the solution robustly to find flaws or risks. Often those risks are unintentional or easy to make even by qualified devs who are following good processes.

Yes you can find stuff like this where someone obviously made a bad call, but much more often you'll find someone simply forgot to add auth middleware to a single endpoint, or did not check for null.

87

u/FunnyObjective6 Aug 29 '26

Are you really nitpicking on the definition of "idiot or intentionally slacked off", which is meant the same way as "blame the previous developer"?

4

u/hedoeswhathewants Aug 29 '26

You think these people are hired to figure out who to blame for flaws?

Identifying what caused the issue is valuable, but they're there to make sure it's secure, not to point fingers.

→ More replies (1)

18

u/ZealousidealTill2355 Aug 29 '26 edited Aug 29 '26

It’s not nitpicking. I also don’t find any value ofsaying someone “slacked off” — because prove it.

They could just not be as smart, or made a careless mistake, even overworked—and a good company recognizes that the system is the issue.

For instance, why is the existence of your whole database reliant on a guy who doesn’t know how or doesn’t have the ability to keep said database safe? And if he’s in that role, why is he not given time and resources to gain that knowledge? Perhaps the possible punishment put them in a position to not bring attention to large vulnerabilities as they’d be a scapegoat. Etc etc

Companies that blame and hold employees accountable for mistakes (such as those that inevitably appear in an audit) are insufferable and toxic. It’s just managements way of abdicating accountability. It pushes the can down the road as the next IT guy can do the same exact thing, because the problem wasn’t actually fixed.

34

u/FunnyObjective6 Aug 29 '26

They could just not be as smart, or made a careless mistake, even overworked

And if you point that out, it would fall under "blame the previous developer". Trying to wedge a different definition in there is nitpicking.

3

u/Still_Elk2103 Aug 29 '26

its not the previous dev's fault if he was overworked......

Nor is it his fault if he wasnt smart enough and/or experienced enough for the job...

→ More replies (6)

7

u/Abe_Odd Aug 29 '26

if you are intentionally using em dashes and directional quotes instead of the normal ", know that you're making your text look AI generated.

→ More replies (13)

5

u/Rough_Bread8329 Aug 29 '26

You're absolutely not nitpicking. Jesus Christ.

I swear it's like no one has ever heard of the concept of Quality Assurance. People are human and make mistakes. An extra pair of eyes is all it takes sometimes to catch something that was simply an honest to God error.

Not malice, not stupidity, not lack of training, not vibecoding, not slacking or laziness, not underqualification. Just a mistake.

"Hey man - can you take a second and look over this code snippet?" can save so much headache and the very thing OP posted about.

5

u/oditogre Aug 29 '26

A writing podcast I listen to once said something that really stuck with me: You want an editor who buys red ink by the gallon.

The only thing keeping you from showing your whole ass to every reader and critic out there with a bunch of hilarious errors - whether they be simple spelling and grammar, or referring to a character or place by the wrong name, or a continuity error, or whatever, is an editor coming along with a fresh set of eyes and carefully picking out all the little errors that every person makes and is blind to.

It blows my mind every time I see a dev with the mindset that QA, code reviews, UAT / stakeholder testing, and anything else standing between their PR and PROD is an adversary to be undermined, resisted, or bullied at every turn, and every mistake found is fixed grudgingly, as if it's somehow the finder's fault, instead of being happy that they spared you from that issue being found by a major client or something.

→ More replies (2)

3

u/LimitedWard Aug 29 '26

It's nothing to do with ascribing blame. It's about identifying gaps. Software security is inherently complex. You can be following industry best practices and still have vulnerable software if you fail to piece those best practices together in precisely the right way.

→ More replies (5)

177

u/JeffSergeant Aug 29 '26

My favourite find was a website with a 'Password Reset' box, the email address was a hidden field, you could reset anyone's password and have it send the email to an arbitrary address.

52

u/HeyGayHay Aug 29 '26

That’s why the dev decided to hide it, duh

44

u/H010CR0N Aug 29 '26

The previous developer was a nepotism hire.

47

u/omnichad Aug 29 '26

Or the actual owner, judging by how offended they seemed to be.

→ More replies (1)

110

u/arcane_Auxiliatrix Aug 29 '26

17

u/Critical-Champion365 Aug 29 '26

How the hell is there an XKCD for everything? Are the modern equivalent of proverbs?

16

u/alinroc Aug 29 '26

He's been at it for a long time. Similar to how The Simpsons has done everything by now.

→ More replies (2)

31

u/reevesjeremy Aug 29 '26

Similar. An internal team was developing a replacement app for an ancient COTS product. When they were about a week away from production launch, they asked a few of the stakeholders to test it to see that it met the requirements. They did not m ask me to do a security assessment on the development environment, just to review it for functionality and features. But it was right there and I had to look. I couldn’t not at least try, right? If not me, who? Our security assessment team apparently didn’t do a good enough job because here is what I found a week away from deployment to production.

1) The password reset question/answers were pulled from the database and stored in hidden fields and used JavaScript to make client-side validation of the input. So as an unauthenticated user, I would have access to read anyones answers and get to know them a little more simply if I knew their username and went to password reset.

2) The login also had JavaScript client-side validation, so I could modify the JavaScript file to bypass the validation, and save it to replace the hosted JavaScript file for that site, then login as anyone simply by entering their username.

3) For every database call, I saw a BASE64 string in Network trace. Decoded it was the database service account credential, instead of using something like JWTs.

I know there were other things I found, they just weren’t as egregious as this.

The deployment of that product was delayed by 2-3 months while they reworked that. Not sure how the devs thought any of that was the right way to do it after collectively so many years in development.

25

u/eladts Aug 29 '26

Not sure how the devs thought any of that was the right way to do it after collectively so many years in development.

  1. Developer A: It is just a proof of concept, I'll fix it later.
  2. Developer A leaves the team.
  3. Developer B: If it ain't broke, don't fix it.

3

u/Sweaty-Willingness27 Aug 29 '26

More like "Product Manager says that's tech debt, and we don't do that here"

→ More replies (4)
→ More replies (7)

7.8k

u/Doctor429 Aug 29 '26

That's one of the rookiest mistakes someone can make while web development/coding.

2.3k

u/xarcastic Aug 29 '26

OP, this is a serious enough flaw that you should not trust that company with your data. Your personal info, credit card info, and that password should all be considered compromised.

683

u/Doctor429 Aug 29 '26

And, OP, if you did purchase anything from the site, consider cancelling and renewing your cards.

→ More replies (11)
→ More replies (1)

288

u/DasBeasto Aug 29 '26 edited Aug 29 '26

I don’t even think its a common rookie mistake, I can’t think of any reason they’d shove the credentials in the url. Plenty of footguns to make in an authflow if you don’t know what you’re doing but this one you’d have to go out of your way to be dumb.

Edit: I’m dumb too, forgot that’s the default behavior of a GET form action, not as the dumb as the person that built that though.

137

u/SF-NL Aug 29 '26

Even tutorials for beginners don't have credentials in the URL. So I agree with you, this isn't even a rookie mistake.

72

u/Valoneria Aug 29 '26

Pretty common mistake if they use a form that uses GET instead of POST. A rookie mistake sonto speak.

53

u/Ok_Entrepreneur_739 Aug 29 '26

Can confirm. My first ever website I built did this, I used GET instead of POST. But I was 16, it was the year 2000 and the website was a stupid thing to mess round with and I learnt stuff. Before long I was storing passwords in a hashed file not kept in the /public_html/ domain like a pro.

8

u/drywallsmasher BLUE Aug 29 '26

It’s alright considering even realizing your mistake not long after 2000 you were still way ahead of the curve, seeing how many times I remember a bunch of popular websites sending me my (not randomized) password as plain text in the signup email until 2015.

28

u/little-bird Aug 29 '26

anyone remember back in the early days of Facebook, you could “hack” other accounts by logging into your own account then changing the profile ID in the URL?  wild times. 

35

u/HirsuteHacker Aug 29 '26

They used a get request rather than a post. It's an incredibly easy mistake to make if you don't know what you're doing. Really speaks volumes about whoever developed their website.

→ More replies (10)

1.6k

u/TommyVe Aug 29 '26

*vibecoding

519

u/NamerNotLiteral Aug 29 '26

Even AI knows it's an insane rookie mistake and will always tell you to separate credentials.

8

u/kaisadilla_ Aug 29 '26

Yup. It's the kind of thing so straightforward that AI will never make the mistake.

121

u/TommyVe Aug 29 '26

Yes, if you ask it right away.

Working on something bigger in one chat, one context window, it starts making a lot of mistakes.

167

u/[deleted] Aug 29 '26

[deleted]

→ More replies (20)

13

u/abandonplanetearth Aug 29 '26

Bruh no not like this. The classifier would probably block it given how dumb it is

41

u/Fit_Entry8839 Aug 29 '26

Not like this. But this is stuff we've seen humans do for forever. It's so funny that people forget that humans used to make huge mistakes well before AI, and are seemingly just attributing errors to AI now with zero proof.

→ More replies (16)

6

u/HirsuteHacker Aug 29 '26

Nah it'll make a lot of mistakes but it won't use a get request for authing, it's too basic a mistake

5

u/ApprehensiveGold2773 Aug 29 '26

LLMs are much better now than you seem to realize. Like, seriously, if you believe they are this bad, you need to start studying before you speak.

5

u/Frenyth Aug 29 '26

Just split the functional requirements, if it's too big for one context window, it's too big for one task. That's more a failure of project management.

→ More replies (3)
→ More replies (4)
→ More replies (15)

34

u/MueR Aug 29 '26

Not even ai makes this mistake. This is the owners cousin handling the website.

40

u/felds ORNAGE Aug 29 '26

That’s not the kind of error that LLMs usually make.

They often fail to follow basic instructions, come up with random requirements, constantly reinvent the wheel, and break stuff by messing with existing working code. This is a huge problem and these mistakes pile up quickly and make codebases unworkable. 

But, for bugs like this, you’ll have to hard “convince” the AI to go down this path. You’ll have to prompt something like “show me how NOT TO send a password”.  

31

u/fucktrance Aug 29 '26

Even AI models wouldn't allow this, that is pure human stupidity at its finest

→ More replies (23)

26

u/Living_Grab_2239 Aug 29 '26

I mean that's some late 90's bullshit a child would make for his/her parent :D

20

u/NoveltyAccountHater Aug 29 '26

Yup. Also, passwords should never be submitted via GET parameters (like in https://example.org/login?username=user&password=p@$$w0rd) and only submitted by POST (over https), because GET parameters that's often stored in your browser history as well as in the web server's log.

Passwords should be immediately hashed with a slow secure hashing function to be compared against the pass in the database.

→ More replies (6)

10

u/ManWhoIsDrunk Aug 29 '26

You used to be able to find a lot of interesting sites if you googled the following:

inurl:select name

It does seem that google has gotten wise to this trick, and no longer lets people find easy database accesses by a simple search string.

10

u/invokes Aug 29 '26

Wow! This is like 1997 awful! 😂

3

u/Cryogenicist Aug 29 '26

Even most rookies know better!

3

u/Expensive-Mention-90 Aug 29 '26

In 2004 I worked at eBay and we found one tiny set of accounts (like a few hundred) that disclosed the email address in the url, and it was a Sev1. That’s over 20 years ago.

→ More replies (24)

803

u/noahesbjerg Aug 29 '26

fun fact: urls get logged everywhere by default. that password is now sitting in plaintext in their server logs, your browser history, and whatever analytics scripts they run via the referer header. auth over GET should be a crime

160

u/omnichad Aug 29 '26

And any web site that is linked to from this page, if there are any and they click it.

21

u/turtleship_2006 Aug 29 '26

Any half decent browser from the last decade with filter the "referer" header to just the domain, not the full URL, e.g. if you clicked a link from Reddit, the other website would only know it was from Reddit, not which subreddit or post

8

u/xarcastic Aug 29 '26

And every ISP and router involved.

16

u/omnichad Aug 29 '26

Well, no. If it runs over SSL.

→ More replies (12)

16

u/rcklmbr Aug 29 '26

It violates GDPR, so it is actually a crime

10

u/ashgs872tbhjs Aug 29 '26

GDPR doesn't define crimes, is a regulatory framework. Closer to civil law, but not even that either. There are a lot of types of illegal things that aren't criminal.

→ More replies (1)

22

u/gameplayer55055 Aug 29 '26

That's why you shouldn't have one password for every website.

Although technically I have one specifically reserved for websites I don't care about

5

u/ACoderGirl Aug 29 '26

Password manager is the way to go. You can basically remember 1 highly secure password and everything else is just generated randomly. It also serves to help you remember if you even have an account for a given site in the first place and to remember usernames for sites that don't use email (or if you use different emails for different sites).

→ More replies (3)
→ More replies (3)

2.9k

u/bfly200 Aug 29 '26

"Everyone can code with AI."

609

u/malou_pitawawa Aug 29 '26

Even AI is better than that actually

153

u/absoluteally Aug 29 '26

Some AI, people doing this might be using a free model.

129

u/whatisuser Aug 29 '26

I don’t even think a free one would do that lol

36

u/MetriccStarDestroyer Aug 29 '26

It will if you tell it to make a simple site.

Do not use any apis, cloud subscriptions, managers or complicated stuff.

35

u/Inevitable_Jury3594 Aug 29 '26

or complicated stuff.

Oh no

16

u/OperaSona Aug 29 '26

It won't. It'll still push common best practices because that's what's the common denominator in its learning data. This type of error isn't something common it may have picked up. It can only exist right next to a note that says "don't do that, instead do this", which the model will have taken into account.

6

u/joshTheGoods Aug 29 '26

Not once have I seen a mistake this big in any of the vibe coded crap my family sends me when they get stuck. I have, however, seen this same mistake (in various forms) maybe half dozen times over the last decade monitoring sites for this exact sort of bullshit... a company that existed before AI, so what does that tell you about how regular this sort of crap is?

→ More replies (1)

5

u/Belzhazzar Aug 29 '26

I don't even think that one that pays me to use it would do that

37

u/DominoNo- Aug 29 '26

No AI would. None of the codebases any model is trained with is this bad

7

u/Annoying1978 Aug 29 '26

Nope. No AI model would this. 

12

u/boblancho Aug 29 '26

I use a free one and is pretty damn good. but I am pretty damn good so

→ More replies (11)
→ More replies (1)

9

u/ruckertopia Aug 29 '26

Absolutely not true. A friend who doesn't know how to code asked me to look at a website he put together with ai, and it was doing exactly this.

8

u/Grays42 Aug 29 '26 edited Aug 29 '26

Then one of four things is true:

  1. Your friend was coding with an old, dirt-cheap, minimal-parameter model on OpenCode or something, even then I doubt it would ever do anything remotely like this

  2. Your friend was sabotaging the model and actively telling it to do the wrong things

  3. This story comes from 2-3 years ago when the models weren't good at this yet

  4. You made this up.

I have been scripting/coding in a hobby and auxiliary-to-my-day-job capacity for 20 years and over the last year switched to heavy use of Codex and Claude Code. Even mid-tier models like Sonnet are excruciatingly careful with credentials and security hygiene, to the point that every single application they build, they are building it like an enterprise-scale Fort Knox.

I regularly have to hip-check their security over-engineering by saying, "calibrate: this is a basement hacking project, no one will touch this but me, and that credential is the definition of low risk, you do not need to be so paranoid."

It is unfathomable that any of even the low-tier frontier models would put a plaintext password in the URL. That's "I have no idea what I'm doing" levels of stupid.

→ More replies (4)
→ More replies (3)

87

u/null_reference_user Aug 29 '26

Pretty much any AI coding agent today will refuse to do that unless you explicitly ask and reaffirm multiple times.

This is human slop and I've seen these things since before AI was even a thing

9

u/Soft_Awareness_5061 Aug 29 '26

Exactly. Not pretty much. Literally no AI would have coded this.

→ More replies (1)

14

u/AttorneyIcy6723 Aug 29 '26

This is absolutely not AI and definitely some kid learning how to create HTML forms for the first time.

10

u/Theezach Aug 29 '26

Yeah I know we like to joke about this but Claude and ChatGPT won’t do this even

→ More replies (22)

201

u/theMightBoop Aug 29 '26

This is why I get irrationally angry over places that make me have overly complicated passwords of various lengths and criteria.

My password is not getting compromised by brute force attacks. It’s because companies store their fucking passwords in plain text and then someone gets a hold of the file. EVERY.FUCKING.TIME.

70

u/treeckosan Aug 29 '26

Ive gotten more "our servers were breached and your data was leaked between 6 and 18 minths ago" letters thsn i have suspicious login attempts over tye last 5 years. And the breach was always at least 6 months ago with the stalest letter saying it was about 18 months since the breach, all the damage has been done by this point.

17

u/Dunom12 Aug 29 '26

Try using a password manager app or extension; they can generate a strong password for you and also store it.

24

u/theMightBoop Aug 29 '26

But my point is the issue isn’t a strong password. The issue is I can make whatever the fuck password, strong or weak, and the issue is the backend server storing it in plain text.

→ More replies (5)
→ More replies (1)
→ More replies (4)

507

u/Occidentally20 Aug 29 '26

That's how you know it's secure - only you can see your own address bar. Hopefully.

103

u/ProbioticOnARobotic Aug 29 '26

Hunter2

63

u/Occidentally20 Aug 29 '26

All I see is *******?

4

u/kranker Aug 29 '26

cool!

you can go hunter2 my hunter2-ing hunter2

→ More replies (1)

8

u/ruusperi Aug 29 '26

With a capital letter AND a number? Now thats progress

→ More replies (2)

68

u/noknam Aug 29 '26

A Dutch journalist joined a zoom meeting of EU defense ministers a while ago because the Dutch one posted a selfie of her infront of the PC, showing the ID and pass in the URL.

21

u/Occidentally20 Aug 29 '26

Genius!

I hope they let the journalist stay for the meeting :)

5

u/BrotherSeamus +2209 Aug 29 '26

It's an older code, sir, but it checks out.

→ More replies (1)
→ More replies (2)

119

u/nguyenhuudailoc Aug 29 '26

That isn't "mildly". If you're using anything with the same password, it's time to change them to something new before you're in big trouble.

26

u/jeanpaulmars Aug 29 '26

If you're re-using passwords, changing them to a unique password per side is a good idea regardless of this.

38

u/Ajax_OG Aug 29 '26

This isn’t even something that could be an honest mistake. This is like, basic security principles. Any developer with even an ounce of brain matter knows that you never store plaintext user passwords, much less IN THE URL.

Likely the result of an incompetent dev who is the sole contributor and blindly accepts whatever it tells them…

7

u/Consider2SidesPeace ORANGE Aug 29 '26

Agreed, so the owners of the site are too cheap to pay for proper site security. This makes me think what other things they are cutting corners on. Unless there are no other alternatives I'd drop them in a heartbeat.

122

u/Live_Life_and_enjoy Aug 29 '26

Top Notch security

You should report that to a security form they will have a field day

11

u/squidgytree Aug 29 '26

Security forum?

26

u/Arszilla Aug 29 '26

Pentester here: this is fucked up on so many levels and likely a big compliance issue - especially given that these requests are logged and saved (on a different level compared to a database). Not to mention a triad of other vulnerabilities that I can think of just because of this being there…

5

u/Adium Aug 29 '26

In the US prescription glasses fall under the protections as any prescription. Tried replacing my own glasses a year after they were prescribed and you’d think I was asking them for an extra bottle of Vicodin or something. Willing to bet they’d fail whatever UK-equivalent HIPAA compliance as well

64

u/HuiOdy Aug 29 '26

Any storing passwords as plaintext and not a salted hash, will have many, many more safety issues.

Also, you can likely hack checkout amounts by basic frontend insertion in your browser.

32

u/Plus_Pangolin_8924 Aug 29 '26

This is them doing a GET on a form rather than a POST. This is HTML forms 101...

7

u/eladts Aug 29 '26

I wonder if the payment form works the same way as the login form.

→ More replies (5)

21

u/Electronic_Amphibian Aug 29 '26

Just to note, this doesn't necessarily mean they're storing the password in cleartext, just that they're not doing proper session management. The password could still be compared to a salted hash on the backend when used to validate the user.

→ More replies (1)

27

u/BinaryHippie Aug 29 '26

In case you forget

13

u/GSxHidden Aug 29 '26

I found one that was worse. Logged into a technician portal that allows you to schedule appointment, set rates, etc in production at work. Turns out if you just inspect the page and go to network, the JSON file they send is THE ENTIRE TECHNICIAN database. What they get payed, how much they charge us, all their bad marks, their real addresses, social. I just closed my laptop and went to lunch.

5

u/canadasleftnut Aug 29 '26

Lmao the reaction to that is too real.

Younger me would've been pumped to find something like that. Today me has seen enough horrors, and know that incompetent and ignorant businesses tend blame good Samaritans for "hacking their website" that I'd definitely walk away. Early lunch sounds better.

12

u/Previous50_Run_53 Aug 29 '26

Change that password wherever you have it. URL parameters get cached. Consider your credentials exposed

12

u/Shaynaenay Aug 29 '26

https://giphy.com/gifs/YWWeEeFThzFS6VKmyX
Me, a newly hired privacy manager taking notes

12

u/mister_neutron Aug 29 '26

That is an impressive level of behind the times. In the early web it was fairly common for sites to work like that but the practice ended a whole long time ago.

11

u/tunaman808 Aug 29 '26 edited Aug 29 '26

Yep. Way back in 1997, before eBay became THE auction site, there were many other competitors: Amazon had auctions, Yahoo! had auctions. There were tons of smaller specialist auction sites for baseball cards, coins, model trains, etc.

There was an IT auction site. I forget the name, so let's call it "IT Auctions" at itauctions.com. They put EVERYTHING in the URL, like so:

http://www.itauctions.com/cgi-bin/auction.cgi?auctionno=1234567&minbid=10&bidinc=5&endtime=604800&userid=12345&category=software

where "AuctionNo" represented the auction number, "MinBid" represented the minimum bid, "bidinc" represented the bid increment and "endtime" was when the auction was to end, in seconds.

You could easily "win" an auction by simply changing "MinBid" to 1 (for $1) and "End" to 10 (for 10 seconds) then reloading the page. The server would happily accept the data and end the auction on your behalf.

I put "win" in quotes because they never actually processed any auction I won. In fact, they called me a dozen times and left several messages on my work voicemail asking how I'd "hacked" their system, and threatened to call the FBI on me!

→ More replies (1)
→ More replies (1)

9

u/eladts Aug 29 '26

Hopefully you aren't using this password anywhere else.

9

u/Nearby_Ad_2519 Aug 29 '26

This is quite literally a textbook example of how NOT to do authentication

9

u/ConfusedOldDad Aug 29 '26

Whoever did their website has no grasp of basic security. If it is in the bar, it is not encrypted, even if the connection itself is. Every company that routes the traffic - your isp and every company between them and the dáta centre that hosts it handles your username and password.

8

u/Zipdox Aug 29 '26

Someone forgot to set method="POST".

8

u/NibblesMcGiblet Aug 29 '26

This reminds me of back in 2011 when I applied for a credit card and then the next page had a response saying I would be notified by email of my approval or denial status but up in the address bar it had “&=denial”.

3

u/VapeSmoker420blazeit Aug 29 '26

what if you manually typed &=approval

3

u/Gold-Supermarket-342 Aug 29 '26

You'd get a $1,000,000 line of credit.

8

u/lontrinium Aug 29 '26

Anybody try entering admin:admin?

8

u/bophed BLUE Aug 29 '26

You should stop using this vendor. This is an old school rookie mistake that shouldn't have happened. Let's say they fix this, what is going on inside their server? Did they encrypt your data? Did they do it right? Hell no, that is a clear sign of a business who is destined to be hacked.

7

u/taybul Aug 29 '26

It's one thing to see your password in plain text in the URL. It's another to realize they're very likely storing it in plain text everywhere else.

7

u/PerspectiveThink4319 Aug 29 '26

Developer here, I found someone doing this on an in-house application that was used by multiple nation's militaries lmao. Thankfully I caught it in one of our non-production environments but this shit does happen.

6

u/G02MaxCodeGreg15off Aug 30 '26

We’ll see more of these shenanigans as ai continues to write and review more and more code.

5

u/Pheore Aug 29 '26

I wanted to order from the site. Is it safe to still?...

17

u/Icarian_Dreams Aug 29 '26

If the website makes such an egregious security mistake, under no circumstances do anything that involves your personal or financial information via it. In fact, it's probably best not to do any sort of business or share any information with the company behind it, because it usually represents their broader approach to cybersecurity, including other systems which they're likely to store your data in.

Take this from someone working in cybersec.

3

u/Pheore Aug 29 '26

Okay, thank you! I'll buy my lenses from a safer website then

11

u/jeanpaulmars Aug 29 '26

if they make this kind of mistakes, i wouldn't trust them. at all.

6

u/Andyrew Aug 29 '26

I use them and they've been good. Really quick shipping. FWIW I'm unable to replicate this bug, the credentials are sent - correctly - as a POST request when logging in.

→ More replies (2)

6

u/AlwaysKinkyDaddy Aug 29 '26

As a Tech Lead for web dev, at least they're obvious about their incompetence.

6

u/Justaticklerone Aug 29 '26

That's some bush league shit right there. That information is potentially readable during transit even with the https connection.

6

u/foley800 Aug 29 '26

Nice, it is right there so you never forget it!
/s

6

u/ArcRiseGen Aug 29 '26

I used to work at those coding bootcamps for full stack web dev and I've never seen a student mess up this bad

6

u/betterwaffle Aug 30 '26

uh... immediately stop, delete your account, and never use this site again. these are the entities that can see your username and password:

  • the operator of network you're connected to
  • the ISP backing that network
  • any intermediary servers that you connect to before connecting to the actual server hosting the website (load balancer, etc)
  • your VPN provider
  • Tor nodes you're routing through
  • software recording your screen
→ More replies (2)

5

u/Original-Reward-8688 Aug 29 '26

Why are all glasses websites fucking malware?

6

u/Aviyan Aug 29 '26

Probably used a self proclaimed IT guy who used AI to write the code.

4

u/Crazym00s3 Aug 29 '26

This is wild. Even if the connection is over SSL urls aren’t encrypted only the body of the request so anyone watching the traffic, including proxies or vpn will be seeing your password.

Did you type your password in and it put it in the URL or was this from a link via email? Which would be even worse as that means the password is stored in plaintext on their end.

13

u/MostImagination007 Aug 29 '26

That is check ✔️ ur eyesight u are not totally blind yet.

→ More replies (1)

3

u/eladts Aug 29 '26

I thought payment processors review the security of sites using their services. I guess I was wrong.

→ More replies (1)

3

u/Frenyth Aug 29 '26

In France a big internet provider (Free) got its database leaked 2 years ago and we learnt that all the password were stocked clearly in the database (without hashing).

4

u/PassionGlobal Aug 29 '26 edited Aug 29 '26

Oh no.

Oh no no no.

Lenstore isn't just showing your username and password in plain text on the bar. If you have DNS-over-HTTPS, it's sending your username and password over to your DNS server too. 

→ More replies (4)

5

u/NorthernCobraChicken Aug 29 '26

Thats about 2 weeks of internal process refactoring and a privilege reduction, possibly role reassignment for whoever let that go

4

u/consumer Aug 29 '26

As a day one web developer (1994), I can't recall seeing this happen or even considered. WTF?

8

u/Due-Arrival-4859 Aug 29 '26

Dunno if it’s cause I’m on mobile, but mine doesn’t 🤷‍♂️

→ More replies (4)

6

u/Lactoseloz Aug 29 '26

This doesn't happen for me. Logged into my account on lenstore and my info is not exposed in the URL. Then added the query parameters and it literally just ignores them. Seems fake / ragebait.

3

u/CaptAwesome4500 Aug 29 '26

As a software developer, my brain wants to die seeing that.

3

u/Kajetus06 Aug 29 '26

thats what happens when people use GET method instead of POST

or was it other way around?

→ More replies (1)

3

u/WorryNew3661 Aug 29 '26

This used to be how the internet worked. I remember accessing porn sites from lists of username/password and entering them into the address bar

3

u/Suitable-Season-4847 Aug 29 '26

Bloody hell. Haven't seen this in the wild since 1999. Looks like vibe coders are giving us all a trip down memory lane.

3

u/phil035 Aug 29 '26

Did someone say gdpr breach!

→ More replies (1)

3

u/xrimane Aug 29 '26

I learned in 1998 not to do this when writing HTML as a hobby. This is beyond unprofessional.

3

u/taybul Aug 29 '26

My BANK did this a long time ago and I emailed them about it. I didn't get a response but a day or two later they announced "improved" security in their online banking system. I'd like to think I had a part in that but more importantly I no longer saw my password in the URL.

3

u/indifferentcabbage Aug 29 '26

Hey claude build me a web app

3

u/ITinnedUrMumLastNigh Aug 29 '26

My first webapp ever wasn't this fucked up

3

u/Super-Estate-4112 Aug 29 '26

Instead of using $_POST they used $_GET.

Rookie ass mistake.

3

u/aliendude5300 Aug 29 '26

I've seen high schoolers make more competent websites.

3

u/D4T45T0RM06 Aug 29 '26

AI will doom us all I swear

3

u/za72 Aug 29 '26 edited Aug 30 '26

I remember fixing this with cookies and using POST, BACK IN 2000

3

u/tiagooliveira95 Aug 30 '26

Vibe coded for sure

3

u/captainguevara Aug 30 '26

Your data is stored in plaintext, nice

3

u/Mariuszgamer2007 Aug 30 '26

Do not use their services at all

4

u/Martyn_X_86 Aug 29 '26

The ICO would be interested to hear about this assuming you're in the UK. If they're dealing with payments too then they could end up in deep trouble with fines to follow.

As a dev with nearly 20 years of experience, this is one of the most basic of basics!

12

u/Ill-Cheesecake7143 Aug 29 '26

Zenni is incredible for glasses, if you haven't ordered yet I'd highly recommend.

5

u/Aquaman1970 Aug 29 '26

Wholeheartedly agree.

2

u/farkingusernames Aug 29 '26

That is so 90's lol

2

u/UnbeatenLoaf Aug 29 '26

That's crazy 🤦‍♂️

2

u/ramriot Aug 29 '26

A dumb but transparent example of why one uses unique strong passwords for each service i.e. reuse exposure from the lowest hanging fruit, gives attackers access EVERYWHERE.

2

u/mrcake123 Aug 29 '26

When you get your 10 year old nephew to build your site

2

u/Legal-Swordfish-1893 Aug 29 '26

Change your password, maybe even get new bank cards, and do not use that site. Consider your information compromised.

2

u/TheNameIsAnIllusion Aug 29 '26

That's a feature, not a bug. If you bookmark the page you get automatically logged in /s

2

u/CriminalMacabre Aug 29 '26

Tell them NICE POST nerds

2

u/UselessDood Aug 29 '26

This is not a site you should ever use.

2

u/Rootsman64 Aug 29 '26

I would close that account immediately. For your own safety, do so now.

2

u/Simple-Charge250 Aug 29 '26

“Vibecoded” garbage. So sick of this shit

2

u/pm_me_DAddario_codes Aug 29 '26

When the CEO’s nephew is “really good with internets”.

2

u/MrSurly Aug 29 '26

Guess what happens if you click out to another website? That gets sent as "referrer" to that website.

2

u/StaticSystemShock Aug 29 '26

At least it's HTTPS connection so it's not exposing both to the entire world along with the URL where to use these credentials lmao. This way it's just "locally" exposing the credentials.

I've seen many wild things through decades, but this is something I've never seen before.

2

u/Serpilot Aug 29 '26

This was the most basic example of what not to do in a cyber security course. This is embarrassing that anyone signed off on this

2

u/nobleone8876 Aug 29 '26

Lul im going to go try known passwords now thanks for the afternoon entertainment