VideoHive

Tuts+ Security Fail

652 posts
  • India
  • Microlancer Beta Tester
  • Beta Tester
  • Has been a member for 4-5 years
  • Referred between 1 and 9 users
  • Helped protect Envato Marketplaces against copyright violations
laranz says
5206 posts
  • Community Superstar
  • Italy
  • Sold between 10 000 and 50 000 dollars
  • Has been a member for 3-4 years
  • Microlancer Beta Tester
  • Beta Tester
  • Repeatedly Helped protect Envato Marketplaces against copyright violations
  • Exclusive Author
  • Author had a Free File of the Month
+2 more
doru says

I’m reading the comment on that blog note

There are no words to express the amount of fail from the envato development team :(

816 posts
  • Attended a Community Meetup
  • Author had a File in an Envato Bundle
  • Bought between 1 and 9 items
  • Contributed a Tutorial to a Tuts+ Site
  • Elite Author
  • Exclusive Author
  • Has been a member for 4-5 years
+4 more
Parallelus says


uhm… did someone mention ssl… 2 million years ago? :D Nevertheless guys, no need to be rude, all systems can be hacked, no matter how awesome they are, there will always be people who find ways around them! :)
As far as I’m concerned, no one blames them for the intrusion, it’s their decision to use a plain text password storage method that everyone is pissed about.

PixelBin is correct. No one is blaming them for getting hacked. It happens to the best of us. The issue is really the passwords not being encrypted.

This is the last time I’ll participate in this discussion. Envato knows they made a mistake. I’m going to wait to see how they handle it moving forward. Every company has it’s stumbling blocks. It’s how they respond and make changes going forward that defines who they are and the value of the company. I have high hopes that this will make them stronger. Time will tell.

177 posts
  • Bought between 10 and 49 items
  • Exclusive Author
  • Has been a member for 2-3 years
  • Referred between 10 and 49 users
  • Sold between 5 000 and 10 000 dollars
xdkd says

Not having https on Envato sites is inexplicable in this day and age.

5 posts
  • Bought between 50 and 99 items
  • Has been a member for 3-4 years
  • United Kingdom
ursad says

Envato response over the next week or two are going be key to how this will be remembered.

https all the pipes!

2934 posts
  • Community Superstar
  • Sold between 1 000 and 5 000 dollars
  • Bought between 10 and 49 items
  • Has been a member for 2-3 years
  • United States
  • Exclusive Author
chrisakelley says

Envato response over the next week or two are going be key to how this will be remembered. https all the pipes!

they’ve already said they couldn’t add https to the sites because of other issues it causes, I can’t find the thread atm though

as for plain text….. come on guys… I get things get hacked, it happens more than most people think but just leaving a wide open door…

on a side note… sucks to be amember

2945 posts
  • Author had a File in an Envato Bundle
  • Bought between 1 and 9 items
  • Elite Author
  • Europe
  • Exclusive Author
  • Has been a member for 2-3 years
  • Referred between 100 and 199 users
+2 more
duotive says

it takes a simple function call to encrypt the passwords and it’s unreversible. what the hell? use this: http://en.wikipedia.org/wiki/MD5 – i now have to think again of new passwords…. the second time. the first time was when you lost control of an account that hacked us all and bought his items from all of our accounts.

355 posts plop
  • Elite Author
  • Sold between 50 000 and 100 000 dollars
  • Grew a moustache for the Envato Movember competition
  • Beta Tester
  • Spain
  • Has been a member for 3-4 years
  • Interviewed on the Envato Notes blog
+3 more
twi says

it takes a simple function call to encrypt the passwords and it’s unreversible. what the hell? use this: http://en.wikipedia.org/wiki/MD5

You should not encrypt passwords only with MD5 function, it’s as bad as plaintext :) Instead you should hash them with salt to have unique stored key.

That’s a shame for envato to let the dev use that method for a so important website! And what it we don’t remember if we have an account there? :/

5206 posts
  • Community Superstar
  • Italy
  • Sold between 10 000 and 50 000 dollars
  • Has been a member for 3-4 years
  • Microlancer Beta Tester
  • Beta Tester
  • Repeatedly Helped protect Envato Marketplaces against copyright violations
  • Exclusive Author
  • Author had a Free File of the Month
+2 more
doru says

many times I asked if we can connect marketplace account with tuts network so we can pay for subscription with the money from the marketplace.

FORTUNATELY envato didn’t do this. :)

(when envato will make me pay for all the stupid jokes I’ve made that will be a fun day) :)

no hard feelings hopefully, you know I love you all.

2000 posts
  • United States
  • Bought between 50 and 99 items
  • Has been a member for 3-4 years
  • Exclusive Author
ThemeOcean says


it takes a simple function call to encrypt the passwords and it’s unreversible. what the hell? use this: http://en.wikipedia.org/wiki/MD5

You should not encrypt passwords only with MD5 function, it’s as bad as plaintext :) Instead you should hash them with salt to have unique stored key.

That’s a shame for envato to let the dev use that method for a so important website! And what it we don’t remember if we have an account there? :/

I would do sha512 + salt.

by
by
by
by
by