So the question is: what is the ethical way to raise the issue and force their hand in a fix?
(Sorry for brevity and spelling; mobile on holiday)
1–10 of 16 posts
So the question is: what is the ethical way to raise the issue and force their hand in a fix?
(Sorry for brevity and spelling; mobile on holiday)
Do you work there? If so, are you willing to lose your job over it?
These sorts of leaks can have devastating effects on the company/customers. You should also think about the employees that work there as well. Are you willing to risk their jobs in the event that the company loses money?
How do you know it's actually plain text? There are plenty of 2-way encryption methods out there. Do you work there? If so, are you willing to lose your job over it? These sorts of leaks can have devastating effects on the company/customers. You should also think about the employees that work there as well. Are you willing to risk their jobs in the event that the company loses money?
I have considered those factors and am definitely concerned. However, consider the other side of the equation: a systems breach that leaves thousands (maybe even millions, given their size and 15 years of operation) of customers data being leaked, potentially leading to fraud and identity theft.
Who deserves to be protected? The organization that will not respond to the threat, or their innocent customers?
How do you know it's actually plain text? There are plenty of 2-way encryption methods out there. Do you work there? If so, are you willing to lose your job over it? These sorts of leaks can have devastating effects on the company/customers. You should also think about the employees that work there as well. Are you willing to risk their jobs in the event that the company loses money?
How do you know it's actually plain text? There are plenty of 2-way encryption methods out there. Do you work there? If so, are you willing to lose your job over it? These sorts of leaks can have devastating effects on the company/customers. You should also think about the employees that work there as well. Are you willing to risk their jobs in the event that the company loses money?
How do you know it's actually plain text? There are plenty of 2-way encryption methods out there. Do you work there? If so, are you willing to lose your job over it? These sorts of leaks can have devastating effects on the company/customers. You should also think about the employees that work there as well. Are you willing to risk their jobs in the event that the company loses money?
What legitimate use case is there for implementing a 2-way encryption method over a hash function for passwords?
Earlier quoted context omitted.
What legitimate use case is there for implementing a 2-way encryption method over a hash function for passwords?
Customer support. A human can then verify the user even if they can only remember a part of the password.