Live data from Hacker News

Virgin Media (UK) stores passwords in plain text, sends them through the mail

twitter.com

51–55 of 55 posts

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#51
post #14
post #3

I learned a long time ago that the default assumption for non-tech-first companies should be deep, deep incompetence, below the level of an undergrad with a decent CS degree, when it comes to basic security practice. Even having your system be Incredibly Important isn't enough to force basic competence: there were plenty of government and bank systems through the 2000s that were apparently designed and maintained by…

"non-tech-first companies" Is an ISP not tech first? Bell labs is an off shoot of a phone company, early computing was based on the efforts of phone companies. Phone companies, which ISPs are the modern variant are the original tech companies. Edit to add: Virgin maintains a fibre optic network so we aren't just talking about a sales front end to someone else's network.

Virgin Media is profit-first, above all else. It's an error to assume that the part of the company that builds out infrastructure is in any way joined up with the part of the company that keeps customers secure (if indeed, they even have people responsible for that, which they apparently don't).

This is why things like GDPR end up being foisted on us. Corporations have proven themselves capable of simply ignoring legislation designed to protect their customers, and simply paying a fine later. They'll secure when it's convenient to them, and not a minute earlier.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#52
post #37

Virgin Media is an ISP, for those who don't know. Perhaps more shockingly, they have a maximum password length of 10 characters, and the first character must be a letter. https://twitter.com/Joshwright10/status/1162811048359014400

Fun fact: you can actually set a good password when you create a virgin media account but then you won't actually be able to login as the password is rejected by their front-end for being too long. And just in case you thought you could do a password reset, their password reset page doesn't work.

I encountered that problem with the payment system for my city water bill a few years ago, I always hoped it would be a problem restricted to small town stuff with no budget for security.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#53
post #14

Earlier quoted context omitted.

"non-tech-first companies" Is an ISP not tech first? Bell labs is an off shoot of a phone company, early computing was based on the efforts of phone companies. Phone companies, which ISPs are the modern variant are the original tech companies. Edit to add: Virgin maintains a fibre optic network so we aren't just talking about a sales front end to someone else's network.

Virgin Media is profit-first, above all else. It's an error to assume that the part of the company that builds out infrastructure is in any way joined up with the part of the company that keeps customers secure (if indeed, they even have people responsible for that, which they apparently don't). This is why things like GDPR end up being foisted on us. Corporations have proven themselves capable of simply ignoring leg…

This model wouldn't seem to explain why eg Google and Facebook have world-class security. You can think whatever you want about the stuff they do intentionally, but I don't think leaving yourself open to hacking is that sound a business strategy for anyone, and I don't think it's a coincidence that more technically-competent companies also tend to be more secure.

Re: Virgin Media (UK) stores passwords in plain text, sends them through the mail

#55

Earlier quoted context omitted.

Virgin Media is profit-first, above all else. It's an error to assume that the part of the company that builds out infrastructure is in any way joined up with the part of the company that keeps customers secure (if indeed, they even have people responsible for that, which they apparently don't). This is why things like GDPR end up being foisted on us. Corporations have proven themselves capable of simply ignoring leg…

This model wouldn't seem to explain why eg Google and Facebook have world-class security. You can think whatever you want about the stuff they do intentionally, but I don't think leaving yourself open to hacking is that sound a business strategy for anyone, and I don't think it's a coincidence that more technically-competent companies also tend to be more secure.

Google and Facebook both started life as tech companies.

Virgin started life as a one-man job hawking records out of a wheelbarrow.

Virgin is not a tech company. Their model is not centered around technology, but content.

Post reply on HN