Live data from Hacker News

Rackspace passwords are visible to customer service

rondam.blogspot.com

1–10 of 41 posts

Re: Rackspace passwords are visible to customer service

#6
post #4

Does the author of this article not know about 2-way encryption? It can be used to store encrypted passwords in a database and the original value can be retrieved.

Letting a random employee to see your password on demand is just as bad as storing it in plaintext. Now the employee knows you and knows your password - for most people that means free access to their mail account, which means free access to all their accounts.

Re: Rackspace passwords are visible to customer service

#7
post #4

Does the author of this article not know about 2-way encryption? It can be used to store encrypted passwords in a database and the original value can be retrieved.

The change password code could also encrypt it in two places - a one-way hash all systems can read for authentication purposes and a second, through one-way link (think crippled RS-232), that stores it in a way only the second system, the one that has no network access, can retrieve using its secret (embedded in hardware) ludicrously large key and only after being enabled by a certain user action and proper multi-human authorization.

But it doesn't matter how ridiculously complex the password recovery system is, allowing meatware to gain access to passwords is a no-no.

Re: Rackspace passwords are visible to customer service

#9
post #5

What part of this conversation proves Rackspace stores passwords in the clear?

Yeah the title is technically wrong. But a hosting provider having access to clear passwords is still atrocious.

They have access to the HARDWARE. They could do anything they wish to with your data. That's why you have things like contracts and trust.

If you're using the same password for more than one account/login, then seriously, that's not a good idea. Don't do it. Ever.

Re: Rackspace passwords are visible to customer service

#10
post #5

What part of this conversation proves Rackspace stores passwords in the clear?

Yeah the title is technically wrong. But a hosting provider having access to clear passwords is still atrocious.

Oh, it's atrocious to give employees access to your passwords, if not unforgivable. However, if we're going to challenge the big guys like Rackspace, we have to do it without making unfounded accusations.
Post reply on HN