4 ms·
and storing plaintext passwords is unacceptable.
by maaark 9y ago
and storing plaintext passwords is unacceptable.
- sillysaurus3 9y agoThat's not true in every case. If you're just throwing it into a DB, then yes. But if you're encrypting it and storing it on an isolated server with the decryption keys on a separate server, it's not a huge deal. Look, people on HN make a massive deal about passwords. One of my most shocking discoveries starting as a pentester was that "storing passwords in plaintext" would be a low-severity finding at best. Medium through critical vulns are reserved for findings that can own an app. That's how little password storage matters. If you're relying on UPS preserving the secrecy of your 21-character master password that you're using across all your websites, you're doing it wrong. Yet the vast majority of users will do exactly that. The way to protect them is for critical services to use 2FA, which they do -- email, phone, insurance, etc all use 2FA or separate 4-digit passcodes now (USAA). There have been so many password database leaks, yet the world moves forward. What is unacceptable is for Blue Cross to leak all your PII, yet the world moved on from that. CloudFlare leaked a huge amount of sensitive info. All of those matter way more than some password leaks. If someone is going to target you, here's the most likely method: https://news.ycombinator.com/item?id=14919845 https://news.ycombinator.com/item?id=14919845
- Piskvorrr 9y agoIf you're using the outlined method, you're very, very far from storing it in plain-text; much further than the woefully common `sha1(passwordtext) // voila, secure!`.
- Jwarder 9y ago> as a pentester was that "storing passwords in plaintext" would be a low-severity finding I suspect that's because you're viewing the situation as a pentester not a user. A plaintext password (on its own) doesn't do a pentester much good until they've already gained control of the system. However, once someone has control of the system then plaintext passwords are a threat to users because a lot of people are vulnerable to common password reuse.
- aeorgnoieang 9y agoBut what's the point of even bothering to encrypt a plaintext password at all, let alone "storing it on an isolated server with the decryption keys on a separate server" unless there's an automated way for a human to see the plaintext?
- ghostly_s 9y agoThey're not plaintext, we ROT-13 encode them first!