The real solution to this is to not use ReplIt. I know it may seem good because it’s free hosting, but user sensitive information such as password hashes should not be stored on there. Also if you use a better solution you can make it not hash tokens, making it perform a lot better.

I bought a database to use but my computer is broken and i won't be able to use it until roughly at the end of june

Well, just saying, having password and token hashes public is basically a data breach and you may be in breach of a few laws for data protection stuff.

For now, I’ll suggest you to temporarily disable login and sharing and do the usual data breach remediation protocol (things like notifying the users, storing the assets, or worse purging the account data)

For now I’ll just wish why I haven’t use Dot’s password.

Or use replit database instead of storing it in a public file, but that has a 50mb limit.

Bundle is shutting down

I’m sorry to hear that. My intentions of pointing out how insecure the database was, was not to get Bundle shut down. I hope you’re able to bring Bundle back one day.

It's because bundle is hard to maintain

View all comments