Live data from Hacker News

Hover.com: we store & email passwords in plaintext for usability

help.hover.com

91–100 of 190 posts

Re: Hover.com: we store & email passwords in plaintext for usability

#91

tl;dr: guy from hover, mea culpa, new code on the way. I thought it might help to provide some further deets on that blog post. I don't think we're making a case there, or providing an excuse - it certainly wasn't my intent to try and convince anyone of anything when I wrote that, but rather, it was an exercise to explain where we were (with that and other development projects) and where we were going. We've gone bac…

Broadcasting this fact is almost as bad of an idea as implementing it in the first place. You now have a bullseye on your site from every blackhat reading this. It's your company and your customers (which I am not one of), so most of the time I would just say do whatever you want, because it doesn't affect me. Problem is, it does. It affects every developer out there, because once your security is compromised and every password is leaked by LulzSec, Anonymous, ScriptKiddies, etc... we're all at risk.

I understand you did this for your users and your product, but please reconsider. Your users are also everyone elses users, so your lack of proper security is shared amongst all of us.

Re: Hover.com: we store & email passwords in plaintext for usability

#92
I emailed a major technology retailer about this when they sent me my password in plaintext. This is the response I got (I pointed out that she made my point for me, but I didn't get another reply)...

Dear XXXXXX

Thank you for your email dated xx/xx/2011. I apologise for the delay in my response.

The only way that people can get your password is to hack into our system or your emails. It has to be sent in plain text for you to know what your password is.

I hope this helps.

Kind Regards

Xxxxx KNOWHOW Customer Support Dixons.co.uk

Re: Hover.com: we store & email passwords in plaintext for usability

#93

Whenever I call up MediaTemple for support, they always ask me my password for verification. Does that mean they also store passwords in plaintext? (serious question)

They still do this??? I was a previous MT customer and I was blown away that they asked me what my password was over the phone. Shortly after, they upgraded their support system with temporary PINs and I've never been asked again.

Re: Hover.com: we store & email passwords in plaintext for usability

#94

Earlier quoted context omitted.

After some positive research, I just purchased two domains from Hover. This is unacceptable however and I will be moving them away. What registrar would anyone say is the most security focused and/or government resistant? Maybe it should be a 2011 AskHN?

I can't vouch for "security focused" - but Gandi.net have so far never let me down. They're based in France, so not susceptible to US law (dependent on the TLD you use of course) and have a huge variety of TLDs. Can't recommend Gandi enough, they do exactly what they say on the tin - "no bullshit".

Gandi also have excellent free DNS hosting services. With an excellent control panel including grouping and raw BIND config.

Re: Hover.com: we store & email passwords in plaintext for usability

#95

Whenever I call up MediaTemple for support, they always ask me my password for verification. Does that mean they also store passwords in plaintext? (serious question)

Not necessarily, they could in theory be entering your password into their computer and seeing if it matches the hash, exactly as if you logged in. But, if they're asking for you to read your password to their call centre down the phone, I'd be surprised if they were that savvy.

I'm not sure it follows that reading the password down the phone is a bad idea ... unless you are calling because you have forgotten it!

My bank has a separate passphrase that I have to use on the phone and I call them rarely enough that remembering it is always a challenge. Asking for my mother's maiden name can hardly be considered secret anymore, and remembering the answers to other security questions is a pain: what did I claim was my favourite movie a year ago?

If I've called them I don't really have a problem reading my password to them. If I don't trust the call center staff I can always change it afterwards.

Re: Hover.com: we store & email passwords in plaintext for usability

#96
post #38

Blaming Hover.com is shooting the messenger. The problem here is that this is what customers want . As long as you ask Hover to compete for business in a race to the bottom of the "convenience" barrel, you are going to have this problem. If Hover stop doing this, someone else wil come along and take Hover's business by sending plaintext passwords around in email. So. You either live with it and do your business with…

The problem here is that this is what customers want And I want a pony, they gonna give me that too? A business transaction is a negotiation between seller and client. You don't always have to give them what they want, and if you are good enough, people won't leave you over that one thing. If you are going to only use sites that store your password in plaintext because it is so damn convenient, you are not going to h…

whoa! I think this may be the first request for a pony on HN.

Re: Hover.com: we store & email passwords in plaintext for usability

#97
post #85

Earlier quoted context omitted.

Quoting you here: "I'd also like to point out that the scope of the risk isn't trivial. For example, URL-based password resets are only as secure as the mailbox they are sent to. i.e. a significant number of domains are stolen and threatened to be stolen through email account exploits (re-registering previously used addresses, forwarding attacks, etc.) This is made even more complex when a domain expires and email on…

"why would your team not opt for things that ARE vetted as being secure, trusted, open, and have widespread adoption?" It was a classic case of letting product management opinion over-ride engineering implications. Namely, on behalf of customer service, I went to bat - hard - with the engineers, to give our CSRs a completely effective way to handle inbound password requests in cases where customers no longer had acce…

Hover customer here. Please don't do this again.

Re: Hover.com: we store & email passwords in plaintext for usability

#98

Earlier quoted context omitted.

After some positive research, I just purchased two domains from Hover. This is unacceptable however and I will be moving them away. What registrar would anyone say is the most security focused and/or government resistant? Maybe it should be a 2011 AskHN?

I can't vouch for "security focused" - but Gandi.net have so far never let me down. They're based in France, so not susceptible to US law (dependent on the TLD you use of course) and have a huge variety of TLDs. Can't recommend Gandi enough, they do exactly what they say on the tin - "no bullshit".

Gandi is super awesome ! One quick thing though: since last year they have a US subsidiary (see http://en.wikipedia.org/wiki/Gandi), which might or might not make them more susceptible to US law.

Re: Hover.com: we store & email passwords in plaintext for usability

#99
post #27

Earlier quoted context omitted.

Yes. They will email your password to you if you click the "forgot my password" link.

ARGH! I just confirmed this. So disappointed. I've changed it now to be completely unique but I wouldn't be surprised if it's logged somewhere.

Damn! Confirmed this as well :(

Re: Hover.com: we store & email passwords in plaintext for usability

#100
post #53

My hosting provider (Bytemark) sends out passwords in plaintext, though I'm not sure if they're stored that way. It is a lot more convenient that having to follow a password reset link, though I'm not entirely convinced by the security/usability trade-off (there's not much on my accounts, since the password simply allows access to the control panel, not root access on the machines).

If you can retrieve the plaintext, it doesn't matter how you store them. Keep in mind, access to the control panel probably means they can CNAME your address over to their own and start dispensing viruses and malware from a look-alike site. Storing passwords recoverably is more or less and unforgivable sin; thinking that it is in any case a good idea is a mark of terrible naivete. Because you're compromising the secu…

AFAIK using simple reversable encryption may prevent a simple SQL injection attack, but of course it won't help if the attacker can gain root on the server, which is much harder though.
Post reply on HN