{"id":791,"date":"2012-04-15T11:37:58","date_gmt":"2012-04-15T18:37:58","guid":{"rendered":"http:\/\/www.nadynerichmond.com\/blog\/?p=791"},"modified":"2012-04-15T11:37:58","modified_gmt":"2012-04-15T18:37:58","slug":"weebly-has-an-obvious-security-flaw","status":"publish","type":"post","link":"https:\/\/www.nadynerichmond.com\/blog\/2012\/04\/15\/weebly-has-an-obvious-security-flaw\/","title":{"rendered":"Weebly has an obvious security flaw"},"content":{"rendered":"<p>A long long time ago, back when Gmail was still in invite-only beta and invites were actually difficult to come by, I snagged nadyne@gmail for myself. \u00a0This has provided years of unintentional entertainment. \u00a0I&#8217;ve amassed quite the collection of other Nadynes who forget their email address or make a typo when entering it.<\/p>\n<p>Today, via a new Nadyne, I learned about a website called <a title=\"Weebly's security is crap\" href=\"http:\/\/www.weebly.com\/\">Weebly<\/a>. \u00a0If you&#8217;re not familiar with it (I wasn&#8217;t before this), it&#8217;s a website and blog creator. \u00a0Since that other Nadyne got her email address wrong when she created her website, I got the confirmation email. \u00a0The confirmation email included a link called &#8220;auto-login to Weebly&#8221;. \u00a0I clicked it, and found myself logged in to Weebly.<\/p>\n<p>Yes, that&#8217;s right: without entering a username or password, I was able to login to someone else&#8217;s Weebly account. \u00a0What fantastically bad security. \u00a0I can&#8217;t possibly be the only person who has received such an email erroneously. \u00a0Weebly should require the user to enter their password when they&#8217;re logging in from a browser that they&#8217;ve never used before, even when clicking on the link from their confirmation email. \u00a0This is such a basic security mistake that I couldn&#8217;t trust them with getting their security right elsewhere.<\/p>\n<p>I can do anything that I like with her website. \u00a0Since I don&#8217;t actually know this other Nadyne&#8217;s email address, I posted something to her new site saying that I&#8217;ve changed her password and that she needs to update her account information with a new password and with her accurate email address.<\/p>\n<p>This collection of other Nadynes has given me a long list of websites that I won&#8217;t do business with as a result of their bad security. \u00a0One particular website actually emailed me, in plaintext, another Nadyne&#8217;s complete information: her real name, address, phone number, SSN (yes, really!), and credit card number. \u00a0Usually I just email the Nadyne in question to let her know that she needs to (a) update her account to reflect her real email address, and (b) be careful about doing business with a company that will send out so much personally-identifying information via email. \u00a0Perhaps it&#8217;s time to mine this for a new series of blog posts.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A long long time ago, back when Gmail was still in invite-only beta and invites were actually difficult to come by, I snagged nadyne@gmail for myself. \u00a0This has provided years of unintentional entertainment. \u00a0I&#8217;ve amassed quite the collection of other Nadynes who forget their email address or make a typo when entering it. Today, via &hellip; <a href=\"https:\/\/www.nadynerichmond.com\/blog\/2012\/04\/15\/weebly-has-an-obvious-security-flaw\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Weebly has an obvious security flaw<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-791","post","type-post","status-publish","format-standard","hentry","category-nadyne"],"_links":{"self":[{"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/posts\/791","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/comments?post=791"}],"version-history":[{"count":2,"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/posts\/791\/revisions"}],"predecessor-version":[{"id":793,"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/posts\/791\/revisions\/793"}],"wp:attachment":[{"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/media?parent=791"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/categories?post=791"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/tags?post=791"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}