← Back to context

Comment by phendrenad2

2 years ago

It's not plain text, it's encrypted via TLS

Well, two counter-points: 1. their TLS implementation isn't secured against MitM attacks. 2. They receive the the full plain text password, not a a hash.

Not sure if it's apparent from the English version of the article, but Heise performed a successful MitM attack to extract the plain text password from the daa stream.