Live data from Hacker News

Major Toronto Utility Company Stores Customers' Passwords in Plain Text

old.reddit.com

21–30 of 89 posts

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#21
post #17
post #10

Earlier quoted context omitted.

Who are you prosecuting?

I believe they're suggesting the people storing the plaintext passwords. Who else would it be?

I guess there's no one person to hold accountable. They probably just get a small fine and move on.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#23
post #19
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

Nice try, Toronto Hydro

I made no such claim. I merely have knowledge of the exact system in question.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#24

Earlier quoted context omitted.

Paying by checks through the mail is so annoying and difficult to stay on top of. I can't understand how you would prefer that approach in general -- is there some strategy here that I'm missing? Or is it that you open mail always immediately when you receive it, and minimize changes in address / vacations? My strategy is to have a "disposable" password that you use for low-value purposes, like paying utilities. I as…

Do you really want to bank on your utility to have their shit figured out so you don't pay the utility bill for your whole town? Even if you do entirely get it resolved, that seems like extra hassle when you could just... use a password manager.

That’s fair, a password manager would be a good (and likely better) alternative. The only reasons I haven’t made the switch:

1. Even password managers are unreliable, with many popular ones getting hacked in the last 10 years. And I don’t like the idea of storing _all_ my passwords with a single service which may be hacked. I suppose I could just store a subset of my passwords, but that eliminates a lot of the convenience

2. I still find password managers somewhat annoying to use in general. Copy-pasting is disabled on many login forms, so I often would have to manually type an unfamiliar password. And when I’m not using my personal laptop I have to “log in twice” to complete a single intended login - this has historically been fairly common for me, though maybe less common recently

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#26
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

There's several alternatives to such an insecure system. That simply isn't the right way to do it.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#27
post #2

This is bad for anyone who recycles passwords. Most everyone I guess. I’m sure they aren’t the only company to do so I don’t think having an online account with your utility provider is required or smart. Good old postal mail is the way.

There is always discussion about people re-using passwords. Why don't more people use something not cloud based like KeePass to keep track of that? I do not get it.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#28
post #21
post #17

Earlier quoted context omitted.

I believe they're suggesting the people storing the plaintext passwords. Who else would it be?

I guess there's no one person to hold accountable. They probably just get a small fine and move on.

Whoever is in charge. That's who you charge. They're the boss. They pay the penalty.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#29
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

My solution to security/recovery questions is to generate or make up ransom answers, and store the question/answer pair in the notes field of the entry in my password manager.

This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#30
I've got news for you - they aren't the only ones. Other big companies in the utilities and financial sector also do this, and even some banks.

Often it's a product of repeated acquisitions, where the lowest common denominator across disparate systems is some kind of text-based format.

That said, I'm surprised a customer service agent ostensibly had access to it.

From my own observations (some made during efforts to champion change), industry has gotten better over time. There shouldn't be cases anymore where salted hashes or other alternatives can't be achieved, and I'm pleased to see the public take security and privacy seriously.

Post reply on HN