Earlier quoted context omitted.
Quoting you here: "I'd also like to point out that the scope of the risk isn't trivial. For example, URL-based password resets are only as secure as the mailbox they are sent to. i.e. a significant number of domains are stolen and threatened to be stolen through email account exploits (re-registering previously used addresses, forwarding attacks, etc.) This is made even more complex when a domain expires and email on…
"why would your team not opt for things that ARE vetted as being secure, trusted, open, and have widespread adoption?" It was a classic case of letting product management opinion over-ride engineering implications. Namely, on behalf of customer service, I went to bat - hard - with the engineers, to give our CSRs a completely effective way to handle inbound password requests in cases where customers no longer had acce…
Hover.com: we store & email passwords in plaintext for usability
121–130 of 190 posts
Re: Hover.com: we store & email passwords in plaintext for usability
#122(What could possibly go wrong?)
Re: Hover.com: we store & email passwords in plaintext for usability
#123> Very quickly, our customer service team was inundated by requests from people that weren’t receiving the email, found the process confusing, and a myriad of other related requests. Wait a second, so customers wont receive an email with a password reset link, yet they'll receive an email with a plain text password? I guess it's possible, but interesting.
Re: Hover.com: we store & email passwords in plaintext for usability
#124Earlier quoted context omitted.
I love this idea. 90% of the time when I use a forgot password link, I'm really trying to auth-by-email. I'm not sure how it would work for reusable links, since that becomes auth-by-URL, which seems significantly less secure— maybe putting HTTP auth in the url would be less likely to be logged at any point?
Isn't this basically the same thing as e-mailing yourself your password?
Re: Hover.com: we store & email passwords in plaintext for usability
#125http://jumba.com.au does this as well; when on the phone to you, they ask you for your password , and the customer support person checks it on their screen . (What could possibly go wrong?)
Re: Hover.com: we store & email passwords in plaintext for usability
#126Blaming Hover.com is shooting the messenger. The problem here is that this is what customers want . As long as you ask Hover to compete for business in a race to the bottom of the "convenience" barrel, you are going to have this problem. If Hover stop doing this, someone else wil come along and take Hover's business by sending plaintext passwords around in email. So. You either live with it and do your business with…
It's not what customers want! Customers don't have a clue. They trust the provider to look out for their interests, since they are not experts. Customers don't understand that receiving a password instead of a reset link means that someone else can take their password. Customers don't know that probably any technical 16-year-old who doesn't like them (or any Hover employee) can figure out a way to break into Hover.co…
Re: Hover.com: we store & email passwords in plaintext for usability
#127Earlier quoted context omitted.
With 100 domains you may want to try contacting Fabulous.com. They live up to their name. You're a bit low on the required names but worth a shot. If you get in, you'll be saving a lot more money and the service is the best in the business.
Thanks. I took a look at Fabulous.com. I recall checking them out once before based on a HN recommendation. They're out of my league. When I say I have 100+ domains, I mean like around 105 (give or take). I'm not really a 'domain professional.' For the reference: > To be eligible for a Fabulous account we > require that you meet at least one of the > following: > Domain portfolio must generate US$750+ per month > Tra…
Re: Hover.com: we store & email passwords in plaintext for usability
#128http://jumba.com.au does this as well; when on the phone to you, they ask you for your password , and the customer support person checks it on their screen . (What could possibly go wrong?)
Are you sure of this? The CSR could also be comparing the hashed/bcrypted/whatever version of the password you give them over the phone to the hashed/bcrypted/whatever version stored in the database.
Given they do this sort of thing, even if they did do fancy hash comparisons when I called them, they still have people's passwords hanging around in plain text elsewhere on the system.
Re: Hover.com: we store & email passwords in plaintext for usability
#129This isn't a microblogging service or pet social network. A domain registrar is storing your password in plaintext? Really? Didn't we go over this a thousand times? If I was on Hover (which I considered), I'd transfer my domains immediately. Moving to a plaintext password system to get fewer support requests is like removing the door from your house so you don't have to keep fumbling for the key.
After some positive research, I just purchased two domains from Hover. This is unacceptable however and I will be moving them away. What registrar would anyone say is the most security focused and/or government resistant? Maybe it should be a 2011 AskHN?
Re: Hover.com: we store & email passwords in plaintext for usability
#130This isn't a microblogging service or pet social network. A domain registrar is storing your password in plaintext? Really? Didn't we go over this a thousand times? If I was on Hover (which I considered), I'd transfer my domains immediately. Moving to a plaintext password system to get fewer support requests is like removing the door from your house so you don't have to keep fumbling for the key.
After some positive research, I just purchased two domains from Hover. This is unacceptable however and I will be moving them away. What registrar would anyone say is the most security focused and/or government resistant? Maybe it should be a 2011 AskHN?