Earlier quoted context omitted.
Whoever is in charge. That's who you charge. They're the boss. They pay the penalty.
They might not know what is being done. They might not even know it is a bad practice. I work in government and you wouldn’t believe how many people are clueless about good practices.
Major Toronto Utility Company Stores Customers' Passwords in Plain Text
71–80 of 89 posts
Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text
#72Earlier quoted context omitted.
Whoever is in charge. That's who you charge. They're the boss. They pay the penalty.
They might not know what is being done. They might not even know it is a bad practice. I work in government and you wouldn’t believe how many people are clueless about good practices.
Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text
#73This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.
My solution to security/recovery questions is to generate or make up ransom answers, and store the question/answer pair in the notes field of the entry in my password manager. This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.
Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text
#74Earlier quoted context omitted.
This is why I choose random but plausible answers. "Mother's maiden name? Cruz-Valdez" "First Concert? Lil' Mermaid" "City you were born in? Ubuntu"
The way I usually do this is with the random article button on Wikipedia, until I find something that sounds plausible.
Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text
#75Earlier quoted context omitted.
Absolutely. Like how many times has my mother's maiden name and the name of my first pet been leaked.
I hate the ones that don’t have a single objective answer. Like “name of your best friend in 3rd grade” or “city where you first fell in love”.
Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text
#76Toronto Hydro isn't just "a major utility company" It is entirely government owned and the largest electricity provider in the province.
It’s been a while since I’ve lived in Toronto but I’m pretty sure neither of your points is correct. I believe you’re thinking of Ontario Hydro, though it looks like that’s been privatized and/or split up.
Happy to be corrected though if I'm misreading this!
Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text
#77Earlier quoted context omitted.
I believe they're suggesting the people storing the plaintext passwords. Who else would it be?
I guess there's no one person to hold accountable. They probably just get a small fine and move on.
Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text
#78This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.
My solution to security/recovery questions is to generate or make up ransom answers, and store the question/answer pair in the notes field of the entry in my password manager. This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.
The "password" here is only used over the phone in place of an account number or similar where a customer can't recall other information.
The reddit user here would have had to provide this password over the phone before to another agent. It's the only way for it to get there.
Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text
#79Earlier quoted context omitted.
I made no such claim. I merely have knowledge of the exact system in question.
Could it have changed since you last saw the system? Because the OP disagrees with you: https://news.ycombinator.com/item?id=41631791
Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text
#80This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.
This is the login password. It was an unintelligable text with non alphabet characters. Source: I posted that on reddit.