Live data from Hacker News

TMobile confirms they store passwords in plaintext, don't see why it's a problem

twitter.com

1–10 of 45 posts

Re: TMobile confirms they store passwords in plaintext, don't see why it's a problem

#4
post #3

Here comes the damage control https://twitter.com/TMobileHelp/status/982334382806454272 Hoping this blows up. Time to short.

I'm not entirely sure, this seems to be US only, we were talking about T-Mobile Austria.

At the end of the day, it's the same company.

Re: TMobile confirms they store passwords in plaintext, don't see why it's a problem

#5

Here comes the damage control https://twitter.com/TMobileHelp/status/982334382806454272 Hoping this blows up. Time to short.

I'm wondering. Why would encrypting the password be any more worse than hashing ? If the private key of encryption is well kept, I don't see why they couldn't do that.

I understand though that no one being able to know the password except the user is utmost security, but why not encrypting it ?

Re: TMobile confirms they store passwords in plaintext, don't see why it's a problem

#7
post #5

Here comes the damage control https://twitter.com/TMobileHelp/status/982334382806454272 Hoping this blows up. Time to short.

I'm wondering. Why would encrypting the password be any more worse than hashing ? If the private key of encryption is well kept, I don't see why they couldn't do that. I understand though that no one being able to know the password except the user is utmost security, but why not encrypting it ?

Because they do not need it for the task at hand. Password security has clear best practices which are also simpler to implement than encryption. The very fact that someone can somehow read your password is a breach of privacy.

Re: TMobile confirms they store passwords in plaintext, don't see why it's a problem

#8
post #6

"Well, what if your infrastructure gets breached and everyone’s password is published in plaintext to the whole wide world?" "What if this doesn't happen because our security is amazingly good? ^Käthe" This is begging for it.

“Excuse me? Do you have any idea how telecommunication companies work? Do you know anything about our systems? But I'm glad you have the time to share your view with us. ^Käthe”

And doubling down as well, that’s a bold strategy.

Post reply on HN