Live data from Hacker News

Virgin Media (UK) stores passwords in plain text, sends them through the mail

twitter.com

21–30 of 55 posts

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#21
post #7
post #2

> Posting it to you is secure, as it's illegal to open someone else's mail. ^JGS (@virginmedia) > There are a number of additional considerations you will need to take account of when designing your password system, such as the use of an appropriate hashing algorithm to store your passwords, protecting the means by which users enter their passwords, defending against common attacks and the use of two-factor authentic…

Perhaps users can pay their bills by leaving a bag of cash in the park with "Virgin Media" written on it, as it would be illegal for anyone else to take it.

In my experience it doesn't make much difference whether you pay the bills or not.

They sent me to a debt collector more than a year after I had closed my account, for something I didn't owe them (it was a bill for services after I had closed my account and been physically disconnected). When I tried to talk to them about it, one of their call centre managers eventually admitted to me that there was no public number that could get me through to a call centre that had anyone able to sort it, or anyone they could transfer me to who could sort it, so I might as well stop trying and sue them.

I got it sorted by tracking down one of the company executives home contact information and calling him about it. I harrassed him considerably less than the debt collectors harrassed me.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#22
post #14
post #3

I learned a long time ago that the default assumption for non-tech-first companies should be deep, deep incompetence, below the level of an undergrad with a decent CS degree, when it comes to basic security practice. Even having your system be Incredibly Important isn't enough to force basic competence: there were plenty of government and bank systems through the 2000s that were apparently designed and maintained by…

"non-tech-first companies" Is an ISP not tech first? Bell labs is an off shoot of a phone company, early computing was based on the efforts of phone companies. Phone companies, which ISPs are the modern variant are the original tech companies. Edit to add: Virgin maintains a fibre optic network so we aren't just talking about a sales front end to someone else's network.

Despite this, they are completely clueless when it comes to technology. I think only a tiny minority of their staff know that they maintain a fiber network, let alone what that means.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#23

Virgin Media is an ISP, for those who don't know. Perhaps more shockingly, they have a maximum password length of 10 characters, and the first character must be a letter. https://twitter.com/Joshwright10/status/1162811048359014400

Last time I checked, the default WPA passphrase for Virgin Media routers was always set to eight capital letters, making it trivially crackable with a reasonable amount of GPU compute.

Talktalk's boxes have the WPA passcode on a removable plastic fob attached to the back of the box.

Great until, like our neighbours, you place the box in your windowsil facing into the room.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#24
Right now in 2019, companies in the UK who somehow now think that they are 'tech companies' have this attitude when it comes to security. I met one company that recently got funding in the UK that deals with personal insurance and asked them if they write tests and they responded that they don't have tests, because they have no time to write any. In this case, that is like not having a security audit because we don't want anyone knowing the secret sauce.

Unfortunately, The motto here is that 'If it ain't broke, don't fix it.' and these systems don't get updated in a while until it is too late.

> Posting it to you is secure, as it's illegal to open someone else's mail. ^JGS

I can't trust Virgin to mail me anything sensitive then as the person who sent these details could have just seen it and wrote it down beforehand. That is too much of a risk to trust anyone and call that secure, even if it is illegal to open someone else's mail.

Well I'll be expecting the GDPR officers to mail you clowns a huge fine then.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#25
post #5

I get everyone replying to virgins Twitter account in disgust, but let’s be honest, the person on the other end of that most likely won’t be technical, nor will there be much chance of them relaying it on. They will reply then go home for the day. This is where things like https://securitytxt.org/ are important. Being able to go through to the team or person who knows what’s going on. But then again, if a company sto…

> I get everyone replying to virgins Twitter account in disgust, but let’s be honest, the person on the other end of that most likely won’t be technical, nor will there be much chance of them relaying it on. They will reply then go home for the day.

Then why are they responding to a technical issue? And you may say they will not pass on information, but it is one channel we have of contacting, possible the only one.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#26

From 2015: "Virgin Media stores user passwords in plaintext?" https://news.ycombinator.com/item?id=9492006

Except now post GDPR implementation it is now illegal to be that incompetent.

Not that I expect Virgin Media to change. They are a massive company with probably a million legacy systems from their NTL, Cable&Wireless and 50 other merges that they will never touch.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#27

Virgin Media is an ISP, for those who don't know. Perhaps more shockingly, they have a maximum password length of 10 characters, and the first character must be a letter. https://twitter.com/Joshwright10/status/1162811048359014400

Last time I checked, the default WPA passphrase for Virgin Media routers was always set to eight capital letters, making it trivially crackable with a reasonable amount of GPU compute.

Must be a while ago then - it's 12 characters upper, lower and digits. Pretty reasonable.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#28
post #14
post #3

I learned a long time ago that the default assumption for non-tech-first companies should be deep, deep incompetence, below the level of an undergrad with a decent CS degree, when it comes to basic security practice. Even having your system be Incredibly Important isn't enough to force basic competence: there were plenty of government and bank systems through the 2000s that were apparently designed and maintained by…

"non-tech-first companies" Is an ISP not tech first? Bell labs is an off shoot of a phone company, early computing was based on the efforts of phone companies. Phone companies, which ISPs are the modern variant are the original tech companies. Edit to add: Virgin maintains a fibre optic network so we aren't just talking about a sales front end to someone else's network.

Yea I know, I considered that someone would raise the fact that they're a telco. It's difficult to articulate what I mean by tech-first, and I don't want to lean on "I know it when I see it", but I'm describing a cluster in thingspace that I think is clear to pretty much everyone here.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#29
post #5

I get everyone replying to virgins Twitter account in disgust, but let’s be honest, the person on the other end of that most likely won’t be technical, nor will there be much chance of them relaying it on. They will reply then go home for the day. This is where things like https://securitytxt.org/ are important. Being able to go through to the team or person who knows what’s going on. But then again, if a company sto…

The person they hired (in all likelihood many people) represents Virgin Mobile in an official capacity. The people in that thread are primarily talking to their followers (because it's Twitter and not a BBS) and are secondarily addressing Virgin Mobile UK. They are not responding to the person you imagine/are assuming must have come up with the Tweet on their own free accord.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#30

Earlier quoted context omitted.

Last time I checked, the default WPA passphrase for Virgin Media routers was always set to eight capital letters, making it trivially crackable with a reasonable amount of GPU compute.

My current default Virgin WPA password is roughly of the form lLlllNllllll (l - lowercase letter, L - uppercase letter, N - number), installed about a year ago, and I know from seeing another one that the position and quantity of the uppercase letters and numbers aren't fixed.

For the benefit of people whose fonts render "l" to look like "|", that's:

L U L L L N L L L L L L

(L - lowercase letter, U - uppercase letter, N - number)

Post reply on HN