Live data from Hacker News

Plain Text Offenders - Did you just email me back my own password?

plaintextoffenders.com

1–10 of 147 posts

Re: Plain Text Offenders - Did you just email me back my own password?

#2
The worst offender I can recall was Wordpress.com. Not only do they email you your password back, but show it to both you and whoever might be sitting within a few metres in LARGE LETTERS in the webpage immediately after activating your account.

After I emailed to complain about this, they said:

"Security and usability is often a trade-off. We make two main ones:

* When you register at WordPress.com, we show you your password and email it to you. * When you log in we tell you whether the username or password was incorrect.

The accessibility and increased convenience for users in both cases has been deemed to be worth it."

Edit: I just checked, and it seems that they've changed this element of their policy. The situation above was March 2009.

Re: Plain Text Offenders - Did you just email me back my own password?

#3
post #2

The worst offender I can recall was Wordpress.com. Not only do they email you your password back, but show it to both you and whoever might be sitting within a few metres in LARGE LETTERS in the webpage immediately after activating your account. After I emailed to complain about this, they said: "Security and usability is often a trade-off. We make two main ones: * When you register at WordPress.com, we show you your…

At least it's some consolation that they don't store the password in plain text, unlike plentyoffish.com. Do they also email you your new password if you change it?

Re: Plain Text Offenders - Did you just email me back my own password?

#4
post #3
post #2

The worst offender I can recall was Wordpress.com. Not only do they email you your password back, but show it to both you and whoever might be sitting within a few metres in LARGE LETTERS in the webpage immediately after activating your account. After I emailed to complain about this, they said: "Security and usability is often a trade-off. We make two main ones: * When you register at WordPress.com, we show you your…

At least it's some consolation that they don't store the password in plain text, unlike plentyoffish.com. Do they also email you your new password if you change it?

Sorry, I didn't clarify: they showed in plaintext the password that I supplied and emailed my password back to me.

Re: Plain Text Offenders - Did you just email me back my own password?

#6
post #3
post #2

The worst offender I can recall was Wordpress.com. Not only do they email you your password back, but show it to both you and whoever might be sitting within a few metres in LARGE LETTERS in the webpage immediately after activating your account. After I emailed to complain about this, they said: "Security and usability is often a trade-off. We make two main ones: * When you register at WordPress.com, we show you your…

At least it's some consolation that they don't store the password in plain text, unlike plentyoffish.com. Do they also email you your new password if you change it?

A secure website should be mathematically incapable of ever displaying your plaintext password in any form whatsoever, at any time, even during the registration process.

Re: Plain Text Offenders - Did you just email me back my own password?

#7
post #4
post #3

Earlier quoted context omitted.

At least it's some consolation that they don't store the password in plain text, unlike plentyoffish.com. Do they also email you your new password if you change it?

Sorry, I didn't clarify: they showed in plaintext the password that I supplied and emailed my password back to me.

Emailing a password after registration does not, in itself, indicate that passwords are being stored in plain text.

Re: Plain Text Offenders - Did you just email me back my own password?

#8
post #3

Earlier quoted context omitted.

At least it's some consolation that they don't store the password in plain text, unlike plentyoffish.com. Do they also email you your new password if you change it?

A secure website should be mathematically incapable of ever displaying your plaintext password in any form whatsoever, at any time, even during the registration process.

How so? You can easily send out an email with the plaintext password, hash it and store it securely from then on..

Re: Plain Text Offenders - Did you just email me back my own password?

#9
post #3

Earlier quoted context omitted.

At least it's some consolation that they don't store the password in plain text, unlike plentyoffish.com. Do they also email you your new password if you change it?

A secure website should be mathematically incapable of ever displaying your plaintext password in any form whatsoever, at any time, even during the registration process.

By that logic, how should the website know what password it should be hashing?
Post reply on HN