Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for
Unencrypted account passwords??? really?
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Feedback
- :
- Plusnet Feedback
- :
- Re: Unencrypted account passwords??? really?
Unencrypted account passwords??? really?
25-11-2015 10:43 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
http://www.theregister.co.uk/2015/11/25/plusnet_still_delivering_passwords_plaintext/
Please tell me this is not true plusnet & you are not storing passwords in plaintext format & arent using unhashed & unsalted strings as verification ?
Not only that I also hope that the following isnt true, please tell me you arent ignoring the advice of the CESG & other security professionaqls & insisting that 'your way is the best way, because thats how you do it' ?
This is exactly how security breaches happen, in much the same way that your email servers dont use any security either. Are we really supposed to just accept this?
Given how lapse the security is & the now advertised risk you are presenting to your users, you seem to be painting an awfully big liability target on your back should anyone lose out if your databases of passwords or other information is ever compromised
Please tell me this is not true plusnet & you are not storing passwords in plaintext format & arent using unhashed & unsalted strings as verification ?
Not only that I also hope that the following isnt true, please tell me you arent ignoring the advice of the CESG & other security professionaqls & insisting that 'your way is the best way, because thats how you do it' ?
This is exactly how security breaches happen, in much the same way that your email servers dont use any security either. Are we really supposed to just accept this?
Given how lapse the security is & the now advertised risk you are presenting to your users, you seem to be painting an awfully big liability target on your back should anyone lose out if your databases of passwords or other information is ever compromised
1 REPLY 1
Re: Unencrypted account passwords??? really?
25-11-2015 10:46 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Moderator Note
Locked in favour of http://community.plus.net/forum/index.php/topic,146131.0.html on the same subject.
Locked in favour of http://community.plus.net/forum/index.php/topic,146131.0.html on the same subject.
Windows 10 Firefox 109.0 (64-bit)
To argue with someone who has renounced the use of reason is like administering medicine to the dead - Thomas Paine
To argue with someone who has renounced the use of reason is like administering medicine to the dead - Thomas Paine
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Feedback
- :
- Plusnet Feedback
- :
- Re: Unencrypted account passwords??? really?