2 ms·
So much fail. They shouldn't even be able to know what your password is. They shouldn't have a copy of it anywhere. Only a hash function (or several) of it.
by DannyB2 7y ago
So much fail.
They shouldn't even be able to know what your password is. They shouldn't have a copy of it anywhere. Only a hash function (or several) of it.
It should be impossible for any of their staff to ever obtain your password, or tell it back to you, or verify that you're reading it to them correctly -- BECAUSE they don't have a copy of your password ANYWHERE.
- Majromax 7y agoFrom the resolution: > So, we came up with a compromise. They would reset my password, log in to my account, fiddle around with it, and then call me with the new password. And so they did. I'm not sure that the staff did in fact have access to the password. It sounds as if they needed to log in as the customer to make necessary changes, so the password request was in the context of a login attempt. Of course, this just raises further questions about how they manage their systems, if they cannot administratively perform any action required without acting as the customer.
- DannyB2 7y agoYes. I got that out of the article as well, but didn't bring it up. In many applications it is important for support staff to be able to access your account in certain ways, but not other ways.