Live data from Hacker News

Major Toronto Utility Company Stores Customers' Passwords in Plain Text

old.reddit.com

1–10 of 89 posts

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#6
post #2

This is bad for anyone who recycles passwords. Most everyone I guess. I’m sure they aren’t the only company to do so I don’t think having an online account with your utility provider is required or smart. Good old postal mail is the way.

Paying by checks through the mail is so annoying and difficult to stay on top of. I can't understand how you would prefer that approach in general -- is there some strategy here that I'm missing? Or is it that you open mail always immediately when you receive it, and minimize changes in address / vacations?

My strategy is to have a "disposable" password that you use for low-value purposes, like paying utilities. I assume this password is public knowledge, and accept that if somebody has it they can do such nefarious things as... pay my utilities bill.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#7
The thing is probably running on decades-old code that makes common security practices (like storing only salted hashes of passwords) hard.

I wouldn't be surprised if there's code in there written in old-style mainframe COBOL or even (gasp) RPG.

Sigh.

Post reply on HN