Pandorhack: Stealing Pandora Passwords
pandorhack.zorinaq.com
pandorhack.zorinaq.com
The default and most secure setting is to not save passwords.
While true from a systems vantage point, it isn't really true once you bring in the human factors. It just isn't reasonable to think people will type in distinct and secure passwords for each of their IM accounts each time they start up their client. It's far more reasonable to have a password manager which manages which applications have access to which passwords, and which stores the passwords all protected by a master password (ideally with two factor authentication).
It doesn't appear that merely cloning a login session cookie would get you access to the password, as it does not appear that the server even knows what it is. In fact, this approach they've used seems like it would allow for password challenges whenever Pandora wanted to, which makes session stealing far less effective.
As fun as they are to read about, I don't care so much about the actual attacks. How to do it wrong is well known.
I am interested in what causes this problem in general. What is causing so many companies to have such abysmal security practices even though we know how to do it better? Can it be fixed?
If the industry does not police this, the government will have to regulate us to ensure compliance with more reasonable practices. That means auditing of our code by independent agencies, paying the fees to do so, suffering the inevitable cases where code is stolen by corrupt auditors, and the foot in the legal door for future and expanding governmental code regulation and auditing at all levels, not just web facing. It would be much better if we could solve this problem ourselves as a responsible industry and avoid the necessity for invasive regulation.
Ok, admittedly, bad form on pandora's part but seems pretty low impact to me.
I suppose these days, in light of the point you make, if you accept a password from an end-user there is no such thing as a low impact disclosure.
The reality is though, what Pandora is doing prevents the password from going over the 'net at all, which arguably protects it from being stolen better. For someone to get access to it, they'd need access to your machine, at which point... just how secure do you think your PayPal and Google accounts (assuming no two-factor auth) will be?
The main increased risk factor if you shared your PayPal and Pandora passwords would be that if someone had read-only access to your filesystem, they could still get your PayPal password (which wouldn't otherwise be the case). This would be a potentially big exposure if you have unencrypted backups (though why backup HTML5 storage or browser data in plaintext to an untrusted target if you want security?) or for whatever reason you let other people read your browser profile directory.
Still doesn't feel like a big deal.