Dangerous default re rDNS
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Feedback
- :
- Plusnet Feedback
- :
- Dangerous default re rDNS
Dangerous default re rDNS
01-02-2013 6:40 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
As suggested by Oldjim in reply to this post I have raised a ticket to stop this.
Surely the default should be not to reveal this? There are only two things preventing a hack, the username and the password, and revealing the first severely compromises the customer's security.
Edit - typo.
Re: Dangerous default re rDNS
01-02-2013 7:58 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Dangerous default re rDNS
01-02-2013 8:12 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Dangerous default re rDNS
01-02-2013 9:08 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Dangerous default re rDNS
01-02-2013 9:30 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Dangerous default re rDNS
01-02-2013 9:46 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Dangerous default re rDNS
01-02-2013 11:07 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Dangerous default re rDNS
02-02-2013 11:09 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Dangerous default re rDNS
02-02-2013 11:22 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
But none of this addresses the basic issue. The default should be to the IP address alone, not the account username. It is simply incomprehensible and very insecure for it to be as it is, without even a warning at request time through the Member Centre.
Re: Dangerous default re rDNS
04-02-2013 10:11 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Dangerous default re rDNS
05-02-2013 9:39 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
With the current default for rDNS on fixed IPs, I potentially reveal my username to every site I visit on the internet. By definition, that therefore reduces the security of my account, although it doesn't breach it. My account is still protected by the complexity of the password I have chosen. Given what we now know about the poor password practices employed by MOST internet users (who are all human, after all), the revelation of the username is significant. It would be good security practice to eliminate this issue.
Re: Dangerous default re rDNS
05-02-2013 2:15 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Just playing devil's advocate rather than trying to say the idea's without merit, we'll make sure it's passed on.
Re: Dangerous default re rDNS
05-02-2013 4:19 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Even then, IT literate people are unlikely to have a 64-character alphanumeric plus special character password ;). Several may also ask for a static IP address just so they can run the TBB BQM, (which is my only need for one), without really being particularly savvy.
Quote from: Matt ... but this only happens with static IPs which wouldn't really be used by less IT literate people?.
How many password attempts are allowed before the system locks the account access please Matt?
Re: Dangerous default re rDNS
07-02-2013 9:59 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Dangerous default re rDNS
07-02-2013 10:20 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Just had reply to a ticket asking for a change to rDNS, have been told that it does not resolve to the ip. However on checking via several sites they all show it resolves to the correct static ip. Come on Plusnet get it right!!!
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page