Live data from Hacker News

Virgin Media (UK) stores passwords in plain text, sends them through the mail

twitter.com

31–40 of 55 posts

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#32
post #8
post #2

> Posting it to you is secure, as it's illegal to open someone else's mail. ^JGS (@virginmedia) > There are a number of additional considerations you will need to take account of when designing your password system, such as the use of an appropriate hashing algorithm to store your passwords, protecting the means by which users enter their passwords, defending against common attacks and the use of two-factor authentic…

VM even got the mail law a bit wrong. The relevant law is the Postal Services Act 2000, section 84(3) If the letter has already been delivered, maybe to the wrong address, it's only an offence to open that letter if you have the intent to cause detriment and you don't have an excuse to open it. "Hey this looks important and I wonder who it's for" is a reasonable excuse to open the letter. https://www.legislation.gov.…

Try telling this to a cop who’s itching to arrest you - back-chat and “being clever” is never appreciated.

My 93 year old neighbour had had people using her address for insurance fraud - I’d spotted the huge pile of unopened envelopes in her kitchen, all sent to her address but with random fictional names. Asked her if I can open one. “By all means,” she says, “I just use them as kindling anyway.” Car insurance policies. Hundreds of them.

So, I did what I thought was the right thing, contacted the fraud line.

A few days later this cop appears, not to investigate the fraud, not to console my neighbour - but to threaten both of us with prosecution for opening letters addressed to someone else - and that was the end of that. Never mind that they were going to her home - if it’s addressed to Miss Xfrjjtgvyes Bstgbfwss then only she can open it. I don’t care that she sounds made up. You don’t know that. How do I know you aren’t made up? Watch that tongue, son.

I ignored him and phoned dozens of insurers on her behalf, didn’t bother the police again. They take opening someone else’s mail, even a fictional person, far more seriously than, say, £30,000 of fraud.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#33
post #5

I get everyone replying to virgins Twitter account in disgust, but let’s be honest, the person on the other end of that most likely won’t be technical, nor will there be much chance of them relaying it on. They will reply then go home for the day. This is where things like https://securitytxt.org/ are important. Being able to go through to the team or person who knows what’s going on. But then again, if a company sto…

Or even a general security page like https://kloudtrader.com/security

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#34
post #14

Earlier quoted context omitted.

"non-tech-first companies" Is an ISP not tech first? Bell labs is an off shoot of a phone company, early computing was based on the efforts of phone companies. Phone companies, which ISPs are the modern variant are the original tech companies. Edit to add: Virgin maintains a fibre optic network so we aren't just talking about a sales front end to someone else's network.

Yea I know, I considered that someone would raise the fact that they're a telco. It's difficult to articulate what I mean by tech-first, and I don't want to lean on "I know it when I see it", but I'm describing a cluster in thingspace that I think is clear to pretty much everyone here.

Is We a tech-first company?

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#35
post #5

I get everyone replying to virgins Twitter account in disgust, but let’s be honest, the person on the other end of that most likely won’t be technical, nor will there be much chance of them relaying it on. They will reply then go home for the day. This is where things like https://securitytxt.org/ are important. Being able to go through to the team or person who knows what’s going on. But then again, if a company sto…

If you are incompetent enough to store passwords in plaintext in your database, the chances that you will be capable of fixing that situation once you find out that's a terrible idea is vanishingly small.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#36

How is it that ISPs are always such awful organisations? I understand that their user base isn’t particularly technical, but there’s no excuse for this sort of public stupidity.

Because the vast majority of them did not start as ISPs. They started as media distribution companies and built an empire based on the value of doing media distribution. Then the Internet came along and made distribution worthless, and the ISP gig was taken up with infinite reluctance.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#37

Virgin Media is an ISP, for those who don't know. Perhaps more shockingly, they have a maximum password length of 10 characters, and the first character must be a letter. https://twitter.com/Joshwright10/status/1162811048359014400

Fun fact: you can actually set a good password when you create a virgin media account but then you won't actually be able to login as the password is rejected by their front-end for being too long. And just in case you thought you could do a password reset, their password reset page doesn't work.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#38

Virgin Media is an ISP, for those who don't know. Perhaps more shockingly, they have a maximum password length of 10 characters, and the first character must be a letter. https://twitter.com/Joshwright10/status/1162811048359014400

Must be a letter and password cannot contain spaces or most punctuation.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#39
post #19

Earlier quoted context omitted.

first character has to be a letter... are they storing them unquoted in yaml files?

Files? If my experience of Virgin Media is anything to go by, they are probably writing them down in crayon on bits of paper that they keep in a very large box, probably outside and open to the weather. Actually, it wouldn't surprise me if they just didn't store them at all and just accepted any login attempt. Given the level of incompetence I have experienced from them, I can only assume they are still in business b…

The actual level of service, speed and response to faults I get from them is pretty good.

The password policy though?

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#40

Does anyone else think the Virgin group companies are really bad and are simply baded on good marketing ? My read on Branson himself is that he's DT with actual billions.

Virgin Media has been owned by Liberty Global since 2013

And Branson only owned 3% before that
Post reply on HN