Live data from Hacker News

Major Toronto Utility Company Stores Customers' Passwords in Plain Text

old.reddit.com

31–40 of 89 posts

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#32
post #2

This is bad for anyone who recycles passwords. Most everyone I guess. I’m sure they aren’t the only company to do so I don’t think having an online account with your utility provider is required or smart. Good old postal mail is the way.

Paying by checks through the mail is so annoying and difficult to stay on top of. I can't understand how you would prefer that approach in general -- is there some strategy here that I'm missing? Or is it that you open mail always immediately when you receive it, and minimize changes in address / vacations? My strategy is to have a "disposable" password that you use for low-value purposes, like paying utilities. I as…

Nice things about checks:

  - not subject to the annoying daily / monthly limits of Interac eTransfers, EFT's, etc.
  - easy to hand to someone, especially where there's no internet
  - generally no extra fees
  - for B2B, pretty much everyone accepts them
  - post-dating (one tactic toward your question of how to deal with regular payments, eg. rent)
  - in the US, a picture of one (meeting certain criteria) has the same legal status as the original
  - float (not nice at all for you, but a not-insignificant revenue stream for your bank/insurance company/etc)
They also fostered a whole soup of fraud prevention practices that is mostly irrelevant to electronic payments yet still seems to pervade and add friction to them.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#33
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

This is the login password. It was an unintelligable text with non alphabet characters.

Source: I posted that on reddit.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#34
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

My solution to security/recovery questions is to generate or make up ransom answers, and store the question/answer pair in the notes field of the entry in my password manager. This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.

How can you be sure that a targeted attack can't exfiltrate all available fields?

For the record, I don't have a great answer to this either -- genuinely curious.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#35
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

My solution to security/recovery questions is to generate or make up ransom answers, and store the question/answer pair in the notes field of the entry in my password manager. This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.

Absolutely. Like how many times has my mother's maiden name and the name of my first pet been leaked.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#36
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

I don't see why the security question answer has to be stored in the clear. If you have to give it over the phone, the agent can type it into a form field that hashes it and compares, just like a password on the site.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#37
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

I don't see why the security question answer has to be stored in the clear. If you have to give it over the phone, the agent can type it into a form field that hashes it and compares, just like a password on the site.

What city were you born in: “Millwaukee”. The agent would be able to tell it was Milwaukee, but if he or she typed “Milwaukee” it’d go “bzzzzt” just because the user typoed the input initially at set-up.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#38
post #37

Earlier quoted context omitted.

I don't see why the security question answer has to be stored in the clear. If you have to give it over the phone, the agent can type it into a form field that hashes it and compares, just like a password on the site.

What city were you born in: “Millwaukee”. The agent would be able to tell it was Milwaukee, but if he or she typed “Milwaukee” it’d go “bzzzzt” just because the user typoed the input initially at set-up.

It's still awful security. city of birth is public info

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#39
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

I don't see why the security question answer has to be stored in the clear. If you have to give it over the phone, the agent can type it into a form field that hashes it and compares, just like a password on the site.

Because security question answer have high variability for the average user. They're asked say, what street they grew up on. Is it "S. Main St." "South Main", "south main", "south main street", etc...

Security questions in general are terrible so don't take this as if it's in defense of them.

My favorite are the presumptive ones that assume something like "Where did you meet your spouse?"

Someone should just go over the top: "Who was the editor of your first successful novel?" "What investment did you make your first billion with?"

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#40
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

I don't see why the security question answer has to be stored in the clear. If you have to give it over the phone, the agent can type it into a form field that hashes it and compares, just like a password on the site.

[deleted]
Post reply on HN