Live data from Hacker News

Major Toronto Utility Company Stores Customers' Passwords in Plain Text

old.reddit.com

71–80 of 89 posts

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#71
post #28

Earlier quoted context omitted.

Whoever is in charge. That's who you charge. They're the boss. They pay the penalty.

They might not know what is being done. They might not even know it is a bad practice. I work in government and you wouldn’t believe how many people are clueless about good practices.

It's literally their job to know.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#72
post #28

Earlier quoted context omitted.

Whoever is in charge. That's who you charge. They're the boss. They pay the penalty.

They might not know what is being done. They might not even know it is a bad practice. I work in government and you wouldn’t believe how many people are clueless about good practices.

Ah yes, the classic "ignorance of the law is a perfectly valid reason to break the law" defense, which famously works all the time.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#73
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

My solution to security/recovery questions is to generate or make up ransom answers, and store the question/answer pair in the notes field of the entry in my password manager. This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.

[deleted]

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#74

Earlier quoted context omitted.

This is why I choose random but plausible answers. "Mother's maiden name? Cruz-Valdez" "First Concert? Lil' Mermaid" "City you were born in? Ubuntu"

The way I usually do this is with the random article button on Wikipedia, until I find something that sounds plausible.

1password team, integrate this feature please

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#75

Earlier quoted context omitted.

Absolutely. Like how many times has my mother's maiden name and the name of my first pet been leaked.

I hate the ones that don’t have a single objective answer. Like “name of your best friend in 3rd grade” or “city where you first fell in love”.

Those are the best! You're supposed to use a random answer like "cookie monster" or "flatulence"

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#76
post #20

Toronto Hydro isn't just "a major utility company" It is entirely government owned and the largest electricity provider in the province.

It’s been a while since I’ve lived in Toronto but I’m pretty sure neither of your points is correct. I believe you’re thinking of Ontario Hydro, though it looks like that’s been privatized and/or split up.

https://www.toronto.ca/city-government/accountability-operat...

Happy to be corrected though if I'm misreading this!

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#77
post #21
post #17

Earlier quoted context omitted.

I believe they're suggesting the people storing the plaintext passwords. Who else would it be?

I guess there's no one person to hold accountable. They probably just get a small fine and move on.

The engineers, just like any other real engineering field.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#78
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

My solution to security/recovery questions is to generate or make up ransom answers, and store the question/answer pair in the notes field of the entry in my password manager. This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.

This is also similar to my solution, however not so relevant here.

The "password" here is only used over the phone in place of an account number or similar where a customer can't recall other information.

The reddit user here would have had to provide this password over the phone before to another agent. It's the only way for it to get there.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#79
post #57
post #23

Earlier quoted context omitted.

I made no such claim. I merely have knowledge of the exact system in question.

Could it have changed since you last saw the system? Because the OP disagrees with you: https://news.ycombinator.com/item?id=41631791

No, the system was updated in August of this year.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#80
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

This is the login password. It was an unintelligable text with non alphabet characters. Source: I posted that on reddit.

The easiest solution is to call them and ask why they have that password and why they can read it. They will verify everything I have already said.
Post reply on HN