Ummm. Google Apps does this.
Boycott websites that send you email with your password in clear text
11–20 of 30 posts
Re: Boycott websites that send you email with your password in clear text
#12I don't think a boycott is the best way to proceed with this problem. For starters, I don't think you will get enough publicity to bring a boycott to critical mass. Secondly, I think it would be more useful and effective to send an email to the perpetrating website, inquiring or complaining about their password storage techniques. When customers/users complain, a good business will respond and attempt to resolve the…
Boycott might be too strong of a word. I just want to bring attention to this point that the user community care about security and this is not a good practice.
Re: Boycott websites that send you email with your password in clear text
#13> Anybody sending you back your password in clear text is also storing it that way in their database Incredibly ignorant statement. If it's encrypted in a reversible format then it's not cleartext. If it's being sent in a confirmation email, then it could even be stored as a one-way hash: password extracted from the form, inserted into email, hashed and stored (This is what WordPress, for example, does). A case can b…
Re: Boycott websites that send you email with your password in clear text
#14For example, for HN, you can use:
orycPASSWORDy
[2 last letters][2 first letters][master password][1 first letter]
Good idea to mix and match numbers in the master password for added security. So for HN it can be: orycpassword1y
The good thing is that you only need to remember a single password for all your sites, yet they are all different. And if you ever forget a password, you can figure out what it was by simply looking at the url.
Re: Boycott websites that send you email with your password in clear text
#15The key is to just use a different password on every site by employing a special password structure. For example, for HN, you can use: orycPASSWORDy [2 last letters][2 first letters][master password][1 first letter] Good idea to mix and match numbers in the master password for added security. So for HN it can be: orycpassword1y The good thing is that you only need to remember a single password for all your sites, yet…
Password schemes like this are still inherently breakable; as soon as someone gets your key password then the rest is trivial to figure out - so why bother with the complication?
Re: Boycott websites that send you email with your password in clear text
#16The key is to just use a different password on every site by employing a special password structure. For example, for HN, you can use: orycPASSWORDy [2 last letters][2 first letters][master password][1 first letter] Good idea to mix and match numbers in the master password for added security. So for HN it can be: orycpassword1y The good thing is that you only need to remember a single password for all your sites, yet…
Re: Boycott websites that send you email with your password in clear text
#17Not sure what is difference that made people care about this but not that, but open to enlightenment.
Re: Boycott websites that send you email with your password in clear text
#18Earlier quoted context omitted.
Incredibly educational comment. I stand corrected that it is not necessarily true that they would store it in clear text in the database but if someone is sending me password in clear text in email I would not give them a lot of benefit of doubt to do the right thing. Besides, what is the utility of sending such an email. If certain software is open source and I can assure they are doing the right thing I will be muc…
I store passwords as a hash in the database, but send it to the user in plaintext when they register. Why? 1. I didn't used to do this, but I got so many requests that I eventually caved. 2. No money changes hands on the site.
Re: Boycott websites that send you email with your password in clear text
#19Ummm. Google Apps does this.
I think Google Apps does this when you are setting up a new user account for other user. Sending that is different as in they need the password to access their account for the first time. Although there are better ways to setup an account and may be gogle app should force the user to change their password on their first login but this is not the same as me setting up my own account and getting an email with my own pa…
Re: Boycott websites that send you email with your password in clear text
#20The key is to just use a different password on every site by employing a special password structure. For example, for HN, you can use: orycPASSWORDy [2 last letters][2 first letters][master password][1 first letter] Good idea to mix and match numbers in the master password for added security. So for HN it can be: orycpassword1y The good thing is that you only need to remember a single password for all your sites, yet…
at this point there's no real reason not to use a random password generator for _every_ site. There are plenty of apps out there for auto login, and / or most browsers will do this for you. Yes, there's some pain syncing with mobile devices but this will go away at some point (modified oauth to validate devices?). Password schemes like this are still inherently breakable; as soon as someone gets your key password the…