Live data from Hacker News

Hover.com: we store & email passwords in plaintext for usability

help.hover.com

151–160 of 190 posts

Re: Hover.com: we store & email passwords in plaintext for usability

#151

Earlier quoted context omitted.

It's not just domain registrars, I reset the password of my basecamphq.com account (which stores very confidential project information) last week, and received this email: Hi -name-, Can't remember your password? Don't worry about it — it happens. We can help. Username: -username- Password: -password in plain text- Please keep your password safe to prevent unauthorized access. It blows my mind that even 37signals fal…

Not exactly a list, but: http://plaintextoffenders.com/

As I'm sure you noticed, many of those sites are putting the password in the welcome/verification email, but this is not the same as actually storing it as plaintext in their database. The thing to look out for is your old password in password reset emails, not welcome emails.

And another one to add to the list: my brother's small business uses British Telecom for email hosting. Their control panel stores the password in plaintext.

Re: Hover.com: we store & email passwords in plaintext for usability

#152
post #149
post #129

Earlier quoted context omitted.

Name.com is great. They don't try to obfuscate the UI to make it more user friendly. Straight access to the DNS records, simple clean design. Here's an old link to a comment I had discussing them: http://news.ycombinator.com/item?id=1766590

That very thread convinced me to switch to name.com six months ago. They're great.

Switched to Name.com around that time too. The website stripped special characters from my password during registration and I couldn't understand why it wouldn't let me log in since the limitation wasn't mentioned anywhere. Had to confirm with customer support. Take that as you will.

But I like how they send you an email on every failed auth attempt.

Re: Hover.com: we store & email passwords in plaintext for usability

#155
post #95

Earlier quoted context omitted.

Not necessarily, they could in theory be entering your password into their computer and seeing if it matches the hash, exactly as if you logged in. But, if they're asking for you to read your password to their call centre down the phone, I'd be surprised if they were that savvy.

I'm not sure it follows that reading the password down the phone is a bad idea ... unless you are calling because you have forgotten it! My bank has a separate passphrase that I have to use on the phone and I call them rarely enough that remembering it is always a challenge. Asking for my mother's maiden name can hardly be considered secret anymore, and remembering the answers to other security questions is a pain: w…

If you're reading it down the phone then you're revealing your login secret to an insecure third party and potentially providing them with the means to log in as you.

Re: Hover.com: we store & email passwords in plaintext for usability

#156
post #38

Blaming Hover.com is shooting the messenger. The problem here is that this is what customers want . As long as you ask Hover to compete for business in a race to the bottom of the "convenience" barrel, you are going to have this problem. If Hover stop doing this, someone else wil come along and take Hover's business by sending plaintext passwords around in email. So. You either live with it and do your business with…

The problem here is that this is what customers want And I want a pony, they gonna give me that too? A business transaction is a negotiation between seller and client. You don't always have to give them what they want, and if you are good enough, people won't leave you over that one thing. If you are going to only use sites that store your password in plaintext because it is so damn convenient, you are not going to h…

I want a pony

http://i-want-a-pony.com/

Re: Hover.com: we store & email passwords in plaintext for usability

#157
post #150

Earlier quoted context omitted.

I'm surprised you haven't been prompted to upgrade your account. 37signals switched to a new login system 18 months ago which doesn't store passwords in the clear. With a new login you get a regular password reset email.

Why should basecamp even need to prompt the user to upgrade their account to the new login system? Why don't 37signals just do it?

Because the newer login system requires you to move away from having any easy to remember username (eg. someperson) that only needs to be unique on a particular Basecamp instance, to picking a harder to remember new username (eg. someperson5946) that needs to be unique everywhere.

Re: Hover.com: we store & email passwords in plaintext for usability

#158

tl;dr: guy from hover, mea culpa, new code on the way. I thought it might help to provide some further deets on that blog post. I don't think we're making a case there, or providing an excuse - it certainly wasn't my intent to try and convince anyone of anything when I wrote that, but rather, it was an exercise to explain where we were (with that and other development projects) and where we were going. We've gone bac…

Fwiw, let me share some of the less predictable consequences of what could happen if your pwd database is hacked, and why it's important to use bcrypt, PBKDF2, or scrypt to secure your users passwords. ( http://codahale.com/how-to-safely-store-a-password/ ) I was one of the folks whose email and password were compromised in the recent MtGox.com bitcoin exchange attack. Until then I had been using a three-tier passwor…

I had been using a three-tier password system, consisting of three passwords of increasing difficulty, used for sites of increasing levels of importance.

Now I'm sitting here wondering what's next, as I can't remember all the sites I used that email/pwd combo on

For my banking password I have a base password that I always add something to for each site in a way that I can remember without having to write something down. The idea being that although it might be obvious to any human looking at the password what I've done it's far more likely that attackers will be automating checking passwords on different sites and the program will just see my password failing on all other sites and ignore it.

Re: Hover.com: we store & email passwords in plaintext for usability

#159
post #73

Earlier quoted context omitted.

I can't vouch for "security focused" - but Gandi.net have so far never let me down. They're based in France, so not susceptible to US law (dependent on the TLD you use of course) and have a huge variety of TLDs. Can't recommend Gandi enough, they do exactly what they say on the tin - "no bullshit".

Gandi is pretty awesome, but just be aware that your credit card company might freeze your card the first time you buy from them (apparently buying domain names in other countries is a fraud trigger) :D

This happened to me, too (twice!), but I now use PayPal instead of my credit card and my bank no longer freezes my account.

Re: Hover.com: we store & email passwords in plaintext for usability

#160

http://jumba.com.au does this as well; when on the phone to you, they ask you for your password , and the customer support person checks it on their screen . (What could possibly go wrong?)

Depressingly, this seems to be a bit of an Australian thing, as iiNet (and the various ISPs they've bought) are guilty of this too.
Post reply on HN