from Hacker News

USPS API bug exposed user data of 60M users

by ZoomStop on 11/22/18, 12:11 PM with 1 comments

  • by ZoomStop on 11/22/18, 12:15 PM

    This is the site that last year had a password reset bug also. When resetting your password the system would generate a random password and email it. During the reset password the current password (the one emailed) is required, and their form validated the old password for the security requirements (length, special character, etc) that the auto-generated reset password did not meet. This effectively locked you out of their site. It took them three months to fix that.

    We absolutely cannot trust this company with our data, yet we have no choice but to do business with them.