12 ms·
Hover.com: we store & email passwords in plaintext for usability
- markbao 15y agoThis isn't a microblogging service or pet social network. A domain registrar is storing your password in plaintext? Really? Didn't we go over this a thousand times? If I was on Hover (which I considered), I'd transfer my domains immediately. Moving to a plaintext password system to get fewer support requests is like removing the door from your house so you don't have to keep fumbling for the key.
- mmahemoff 15y agoPrecisely. Doing something like this is always a trade-off, and yes, it might make sense for something like a blogging service (the same way Posterous inbound mail has the small potential to go wrong), so I can see where Hover is coming from. But really, in the case of a domain registrar, wow. If you're administering a domain, you're no longer in "mainstream user" territory. There should really be some minimal set of conditions for domain registrars, with one of them specifying a reasonable security model for password retrieval.
- mishmash 15y agoAfter some positive research, I just purchased two domains from Hover. This is unacceptable however and I will be moving them away. What registrar would anyone say is the most security focused and/or government resistant? Maybe it should be a 2011 AskHN?
- AdamGibbins 15y agoI can't vouch for "security focused" - but Gandi.net have so far never let me down. They're based in France, so not susceptible to US law (dependent on the TLD you use of course) and have a huge variety of TLDs. Can't recommend Gandi enough, they do exactly what they say on the tin - "no bullshit".
- jarin 15y agoGandi is pretty awesome, but just be aware that your credit card company might freeze your card the first time you buy from them (apparently buying domain names in other countries is a fraud trigger) :D
- Maxious 15y agoNever had that problem with Gandi but buying digital goods from Facebook froze my card. Apparently they were a hive for credit card thief testing at that point in time because of the low value of virtual gifts (1 US cent?).
- christefano 15y agoThis happened to me, too (twice!), but I now use PayPal instead of my credit card and my bank no longer freezes my account.
- geocar 15y agoI've had other positive experiences with Gandi.net: They hooked one of their VPS servers up with a BGP feed so I could announce my AS there for testing a new Anycast service.
- gregsadetsky 15y agoGandi is great and resilient. I know from personal communication with them that the Yes Men recommend using their domain services (they also favor joker.com, which is based in Germany -- I've had a good experience there as well, although Joker doesn't offer VPS services like Gandi).
- AdamGibbins 15y agoGandi also have excellent free DNS hosting services. With an excellent control panel including grouping and raw BIND config.
- stfp 15y agoGandi is super awesome ! One quick thing though: since last year they have a US subsidiary (see http://en.wikipedia.org/wiki/Gandi http://en.wikipedia.org/wiki/Gandi), which might or might not make them more susceptible to US law.
- shantanubala 15y agoI absolutely love NearlyFreeSpeech.net for domain registration (and also cheap hosting). I wouldn't say they're security focused, but they allow you to be totally anonymous in your registration, and have a policy of hosting anything that isn't illegal.
- clobber 15y agoMoniker
- jjcm 15y agoName.com is great. They don't try to obfuscate the UI to make it more user friendly. Straight access to the DNS records, simple clean design. Here's an old link to a comment I had discussing them: http://news.ycombinator.com/item?id=1766590 http://news.ycombinator.com/item?id=1766590
- brodd 15y agoThat very thread convinced me to switch to name.com six months ago. They're great.
- dmit 15y agoSwitched to Name.com around that time too. The website stripped special characters from my password during registration and I couldn't understand why it wouldn't let me log in since the limitation wasn't mentioned anywhere. Had to confirm with customer support. Take that as you will. But I like how they send you an email on every failed auth attempt.
- jjcm 15y agoHere's a thread discussing DNS registrars from last year: http://news.ycombinator.com/item?id=1766439 http://news.ycombinator.com/item?id=1766439
- yawniek 15y ago007names.com is doing good here
- mmatants 15y agoCompanies like Hover have a user/password scenario unlike e.g. an email provider: users only visit their site one/two times a year (to renew a domain or whatever). So I wonder if they should instead allow "authentication-by-email". Basically, make it work just like current reset emails (with an embedded randomized link that allows access), but prevent the link from expiring. Obviously that suggestion has a lot of holes in it, too, but it's something to consider, especially since it's not a new idea. Either way, it's a real amateur move to do away with hashing.
- Cushman 15y agoI love this idea. 90% of the time when I use a forgot password link, I'm really trying to auth-by-email. I'm not sure how it would work for reusable links, since that becomes auth-by-URL, which seems significantly less secure— maybe putting HTTP auth in the url would be less likely to be logged at any point?
- makmanalp 15y agoIsn't this basically the same thing as e-mailing yourself your password?
- woodall 15y agoNot if the link can time-out or expire after X [days, minutes, seconds, ect]. When I think of emailing my self the password, I think of storing it in plain text in my email account. When I think of authentication via email I think of a one time use link that allows me to log into a session.
- repsilat 15y agoEmail is sent in plaintext. It'd be easy enough for an attacker to request an email authentication (which it then sniffs in transit). Expiry time doesn't help much. Email auth really should be done as Joakal says - your public key stored on their server when you sign up, email auth is encrypted. Trouble is, it's "too hard" for "normal people". If gmail/outlook etc supported it, though, it could catch on.
- NiekvdMaas 15y agoIt's not just domain registrars, I reset the password of my basecamphq.com account (which stores very confidential project information) last week, and received this email: Hi -name-, Can't remember your password? Don't worry about it — it happens. We can help. Username: -username- Password: -password in plain text- Please keep your password safe to prevent unauthorized access. It blows my mind that even 37signals falls for this trap. There should be a website showing a blacklist of services that store passwords plaintext.
- alexmuller 15y agoNot exactly a list, but: http://plaintextoffenders.com/ http://plaintextoffenders.com/
- robtoo 15y agoAs I'm sure you noticed, many of those sites are putting the password in the welcome/verification email, but this is not the same as actually storing it as plaintext in their database. The thing to look out for is your old password in password reset emails, not welcome emails. And another one to add to the list: my brother's small business uses British Telecom for email hosting. Their control panel stores the password in plaintext.
- alinajaf 15y ago> The thing to look out for is your old password in password reset emails, not welcome emails. What's the use of encrypting your passwords when you're broadcasting them to every mail server between your and your customer?
- mcobrien 15y agoI'm surprised you haven't been prompted to upgrade your account. 37signals switched to a new login system 18 months ago which doesn't store passwords in the clear. With a new login you get a regular password reset email.
- 15y ago
- scottkrager 15y agoAt least they make a case for it. Security isn't just how you store passwords.
- politician 15y agoPersonally, I've decided to take the position that password security is the "canary in the coalmine" of a business's awareness about security concerns. The degree to which they aren't protecting user passwords correctly likely predicts the degree to which they aren't aware of SQL injection or XSS vulnerabilities.
- scottkrager 15y agoThat's a very good point.
- davidkatz 15y ago+1
- reitzensteinm 15y agoThey are sacrificing the security of their customers for business reasons (usability will increase retention). If they get hacked, if/when they send out a disclosure they'll just say that personal information may have been leaked. Sure, they've made their case for it, but it's only slightly less disconcerting than if they didn't know what a hash is. Actually, it's probably worse, because at least someone that doesn't know about hashing could be educated - these guys have shown that they put profit above protecting their customers.
- beaumartinez 15y agoNo, but it's pretty damn important. All it takes is one disgruntled employee, one uninformed sys-admin, one mistake, and boom, all that "security" is gone.
- AlexandrB 15y agoTheir rationale doesn't make sense to me. If they wanted the same recovery process, they could just send you a new, generated password in a recovery email instead of keeping your actual password in plaintext.
- dieselz 15y agoI take this approach to security: I do everything I can possibly think of to secure an application. Any barrier that you setup now could save you 100x the time (& pain) later. Saying that one part is secure enough is asking for trouble.
- JohnsonB 15y agoCouldn't they at least encrypt it, and store the key on a separate file? *edit: I just want to be clear, I don't actually think encryption would a sufficient replacement for a good hashing function, the question was just pointing out how bad this decision by Hover was; not only do they decide to make the password recoverable, but they don't even take whatever meager opportunities there are to make it at least somewhat secure.
- ori_b 15y agoWhat good would that do? If an attacker gets in, they can get the key just as easily as they can get the database.
- jfong 15y agoIt just adds one more wall but a short wall at that.
- JohnsonB 15y agoNot necessarily, if they hack into one system then getting into another isn't automatic. If the passwords are in a separate filesystem/database than the key, and linked only with software, then unless it's the software that's comprised it would still increase the difficulty of getting both the password and key significantly. It also prevents trivial browsing of passwords via sql commands by rouge employees.
- HaloZero 15y agoBut if you encrypt it with a key, then SQL injection attacks can't collect passwords as easily. You need to hack in and get the actual key to decrypt.
- __david__ 15y agoWith symmetric encryption, probably (assuming the data wasn't gleaned with a purely SQL injection attack). With public key/private key encryption you could probably do it more securely by not letting the private key anywhere near the main app/web servers. Of course, the more separation you have between the public and private keys, the less convenient it is to actually do anything useful with the plaintext.
- 9ec4c12949a4f3 15y agoSweet, thanks for the free paypal/facebook/google/ebay/bank logins!
- geuis 15y agoI've considered using Hover and switching away from Godaddy, particularly since Hover is recommended frequently on the TWiT network. That thought has instantly evaporated. You absolutely cannot store passwords in plain text. There is no level of security you can wrap around the database that will ever be 100%. It only takes one mistake for everything to get exposed. To try and reason that there is a trade off between customer support and security is ludicrous. Your reset emails aren't getting through? Work on fixing that damn system instead of exposing your customers to a world of hurt down the road.
- scottkrager 15y agoOne word: sendgrid
- davidkatz 15y agoscottkrager: do you have any experience with postmark? any thoughts on how they compare? thanks!
- PonyGumbo 15y agoI use Postmark, and I like them very much.
- scottkrager 15y agoI don't sorry. I just know our mail gets inboxed and we use sendgrid.
- xorglorb 15y agoDreamHost also stores passwords in a recoverable fashion, FYI.
- shennyg 15y agoWhich ones? the panel?
- edgardcastro 15y agoI knew bcrypt/scrypt was just a hype! ;)
- joshontheweb 15y agoW T F. I just opened an account with them. Im not too happy. Always seems disrespectful of companies to do that. I think they should at least inform you before you make the account that they are sacrificing your privacy and security in order to cut down on customer service requests.
- macmac 15y ago"Sorry sir, we really don't know how much money is suppose to be in your account. Our developers thought that transactions added too much overhead, so they decided to drop them to insure that the increased response time wouldn't anoy our customers."
- bkorte 15y agoDamnit, transferring domains is such a pain in the ass.
- alexmuller 15y agoI emailed them about this a few months ago after being spurred on by the creation of plaintextoffenders.com: > I received this email when I registered with you last year, and was prompted by the recent creation of the site 'Plain Text Offenders' to send it to them. Somebody else has submitted their registration email too: The reply was as follows: > We realized that this area was of great concern to many customers and we have since removed password submission in our 'Welcome' email. So to give their customers peace of mind, they made it less obvious that what they're doing is stupid.
- wccrawford 15y agoMaybe this is all an elaborate practical joke. Or maybe they wanted to test their security, so they're putting out an all-call to every blackhat out there. Because either of those makes a lot more sense than what they've said.
- naner 15y agoThis really isn't that uncommon. When forced to choose between easier customer support or ostensibly better security practices, easier customer support usually wins. Stolen passwords through email/eavesdropping are rare enough that they can deal with it on a case-by-case basis. If someone somehow gets access to the entire database of passwords (also rare) then they have other security issues that likely would have been a problem no matter how they stored passwords. If company X hashes your password on their server you still don't know that they did it properly or how good the rest of their security is. Basically the only way this differs is that you when you forget your password, your actual password sent in plaintext over the network and is now sitting in your email account. That makes me uncomfortable so I change it right away. Which is the exact same set of steps you would use for a hashed password reset. Everybody focuses on the hashing thing like it is some kind of impenetrable defense or crystal ball into a company's security practices. It is not.
- pavpanchekha 15y agoYou miss the problem --- it's not that hackers get access to your Hover password. It's that for most people, they get access to all of their other passwords, since they're all the same. Also, stealing Hover passwords by wiresniffing must be done on a case-by-case basis, or at least by small geographic neighborhood; stealing them via a database dump can be done en mass.
- brendoncrawford 15y agoThis seems like a good time to mention that I highly recommend using the Password Hasher extension if you are on FireFox. It does help to alleviate problems like this: https://addons.mozilla.org/en-US/firefox/addon/password-hasher/ https://addons.mozilla.org/en-US/firefox/addon/password-hash...
- raganwald 15y agoBlaming Hover.com is shooting the messenger. The problem here is that this is what customers want. As long as you ask Hover to compete for business in a race to the bottom of the "convenience" barrel, you are going to have this problem. If Hover stop doing this, someone else wil come along and take Hover's business by sending plaintext passwords around in email. So. You either live with it and do your business with someone who has decided to offer a "premium" service and has a business model catering to educated customers, Or: You look for the government to regulate the marketplace as a public good. We do this with things like the safety of cars, we've decided that the marketplace cannot be left to decide this for itself. We attempt to do this with things like the content and handling of food, we've decided that the marketplace cannot be left to decide this for itself. Perhaps the security of your account is not important enough to impose regulation. Perhaps it is. But as long as it's left up to the marketplace, the existence of companies like Hover is inevitable, and waggling our fingers at them is not going to do anything except make us feel smarter than the average bear.
- frossie 15y agoThe problem here is that this is what customers want And I want a pony, they gonna give me that too? A business transaction is a negotiation between seller and client. You don't always have to give them what they want, and if you are good enough, people won't leave you over that one thing. If you are going to only use sites that store your password in plaintext because it is so damn convenient, you are not going to have much Internet left.
- raganwald 15y agoYou know this and I know this, but the way the marketplace works is that if nobody intervenes, people buy food that kills them, cribs that kill their babies, pajamas that catch on fire and stick burning plastic to their skin, and so forth. So we draw a line somewhere and say that those products and services over there, caveat emptor. These over here, OTOH, must have a minimum standard of safety. I am personally not convinced that domain registration should be left up to the marketplace. What if someone gets a user's password and then redirects their web addresses to a site that dispenses malware? The victims in this case aren't even the domain registrar's customers, they're people who had absolutely no say in the question. But any ways, I wasn't really trying to suggest we regulate it so much as suggest that laughing at Hover.com is looking in the wrong direction. There is a large social problem isomorphic to the "disable your security software if you want to see a video of dancing babies" problem. That problem is far more interesting and important than the "greedy businesspeople are greedy" problem.
- krashidov 15y agoI guess these guys have taken a fondness to the Anti Security movement... On a more serious note though its dangerous enough to store passwords in plain-text, announcing it to the world is a bit stupid.
- dexen 15y agoPlease correct me if I'm wrong, but... storing password hashes (actually key derived from password) is only meant to secure up password re-use. If there is any other reason, please disregard the text below and just correct me ;-) Isn't password re-use a social problem rather than technical one? Perhaps we ought to use a different -- social -- measure to prevent password reuse. Throwing technical solutions onto social problems doesn't seem to work. Proposal: let's store all passwords plaintext and force users not to re-use passwords, ever. Let's have every password-using service and system make available hashes (derived keys, to be exact, bcrypt() style) of the passwords completely public; when a person tries to create a new account, the service would check a good bunch other services against password hash matches. If the new password (used upon registration) hashes to the same value as on any checked service, the user is rejected and publicly shamed for endangering the service and his account. More checks cound be performed after the registration in background, to lessen the delay on registration. That's it. Social problem, social solution.
- kogir 15y agoYou're wrong. I use hashes so that if somehow the hashes and salts leak the attacker can't now log in as any user with no additional effort. While it's true that a hash compromise typically means you're owned, not having plaintext passwords available still makes further exploitation slightly harder. For instance, read only SQL injection that leaks hashes won't let the attacker write anything.
- AlexandrB 15y agoFor most people the social solution creates a worse usability problem than the one Hover is trying to fix. With unique passwords, the user is now responsible for maintaining (and securing) a list of passwords. Password managers can help here, but this assumes that the password manager doesn't have exploitable vulnerabilities of its own. In addition the password manager may not be accessible when not using the "home" computer.
- pavpanchekha 15y agoSocial problems can get technical solutions. That distinction in bullshit and should be educated out of the Hacker populace. Password reuse (which, BTW, is not why we hash passwords) can be solved otherwise; for example, you can hash passwords client-side and then again server-side, both times salting with a unique salt. That way, the password itself is uniquified in a non-reversible way by your salt (which is presumably not used elsewhere). Your client-side hash can be very expensive, since it's done on the client, and the password you recieve (the hash, that is), is guaranteed unique.
- pittsburgh 15y agoIn the past few weeks, we’ve discussed a new approach that we think will strike a better balance by giving our customers greater control over password management and at the same time ensuring the basic security of those passwords. I’m personally very pleased that our approach will have appeal to customers that are concerned about password security and customers that appreciate the benefits of great usability (and for customers who are concerned about both, blow their socks off Could anybody find the blog post they are referring to that explains their balance between simplicity and security? I was unable to. However, it does appear that they still send plaintext passwords via email: https://www.hover.com/send_password https://www.hover.com/send_password If you're looking to switch registrars, I can't say enough good things about http://gandi.net http://gandi.net. Their motto is literally "no bullshit" and it's the reason I switched to them a few years ago. They aren't the cheapest option, but their UI is very simple and aesthetically pleasing, they offer free DNS hosting, they don't clutter their checkout pages with any ads or ridiculous upsells, they don't kill elephants for fun ( http://mashable.com/2011/04/01/bob-parsons-elephant-story/ http://mashable.com/2011/04/01/bob-parsons-elephant-story/ ), and they don't email your password in plaintext. There are very few companies I'm willing to rave about, but Gandi is one of them.
- SkyMarshal 15y agoSecond all of that about Gandi. They also seem to offer more TLD's than most of the mainstream US-based registrars.
- shapeshed 15y agoSQL injection anyone? I hope the app is secure
- eam 15y ago>Very quickly, our customer service team was inundated by requests from people that weren’t receiving the email, found the process confusing, and a myriad of other related requests. Wait a second, so customers wont receive an email with a password reset link, yet they'll receive an email with a plain text password? I guess it's possible, but interesting.
- kgermino 15y agoIt's not that they don't get the email so much as they don't understand it. Where I work, I make a new account for someone, then send them a password reset email asking them to create a password for themselves, and a personal email writteden by me explaining exactly what they need to do (go to this other email, click the link, enter your new password twice, hit enter, then log in) and I still have 1 in 4 result in support requests. Usually along the lines of "I don't know how to log in because I don't know what my password is.".
- pavel_lishin 15y ago> It's not that they don't get the email so much as they don't understand it. Wouldn't hiring a writer and a designer for a day to re-design the e-mail so that it's more obvious and easy to understand be a better solution than storing passwords in plain text?
- arihant 15y ago"Very quickly, our customer service team was inundated by requests from people that weren’t receiving the email, found the process confusing, and a myriad of other related requests. " What I read - Because we aren't smart enough to create an automated password recovery that works, you should now trust that we are smart enough in network security to safeguard your passwords. Also, these guys mention that they were receiving multiple requests. But how many requests came per user? If you got a million users and they each forget their passwords once a year and have to spend 5-10 minutes resetting it, I don't think its a usability problem at all, even if I get 1 million mails a year complaining about it. Its a bad decision for company handling domains and credit cards. And even if these guys really are good enough to secure their end of systems, whats the guarantee that my inbox is not compromised?
- pavel_lishin 15y agoTen million minutes is approximately nineteen years. That might indeed be a usability problem.
- chrisjsmith 15y agoArrogant idiots! Nothing more can be said.
- rkudeshi 15y agoWhenever I call up MediaTemple for support, they always ask me my password for verification. Does that mean they also store passwords in plaintext? (serious question)
- eftpotrm 15y agoNot necessarily, they could in theory be entering your password into their computer and seeing if it matches the hash, exactly as if you logged in. But, if they're asking for you to read your password to their call centre down the phone, I'd be surprised if they were that savvy.
- aquark 15y agoI'm not sure it follows that reading the password down the phone is a bad idea ... unless you are calling because you have forgotten it! My bank has a separate passphrase that I have to use on the phone and I call them rarely enough that remembering it is always a challenge. Asking for my mother's maiden name can hardly be considered secret anymore, and remembering the answers to other security questions is a pain: what did I claim was my favourite movie a year ago? If I've called them I don't really have a problem reading my password to them. If I don't trust the call center staff I can always change it afterwards.
- eftpotrm 15y agoIf you're reading it down the phone then you're revealing your login secret to an insecure third party and potentially providing them with the means to log in as you.
- deleted 15y ago[deleted]
- jasonbarone 15y agoThey still do this??? I was a previous MT customer and I was blown away that they asked me what my password was over the phone. Shortly after, they upgraded their support system with temporary PINs and I've never been asked again.
- pwaring 15y agoMy hosting provider (Bytemark) sends out passwords in plaintext, though I'm not sure if they're stored that way. It is a lot more convenient that having to follow a password reset link, though I'm not entirely convinced by the security/usability trade-off (there's not much on my accounts, since the password simply allows access to the control panel, not root access on the machines).
- pavpanchekha 15y agoIf you can retrieve the plaintext, it doesn't matter how you store them. Keep in mind, access to the control panel probably means they can CNAME your address over to their own and start dispensing viruses and malware from a look-alike site. Storing passwords recoverably is more or less and unforgivable sin; thinking that it is in any case a good idea is a mark of terrible naivete. Because you're compromising the security of yourself, your users, and any other accounts on any other services that your user uses.
- pwaring 15y agoDNS is handled separately, so there's no chance of any of my domains being 'taken over'. The control panel doesn't actually allow you to do that much, and changes to the billing contacts result in a confirmation email being sent. As for password storage, it's possible that they are encrypted, with the private key held on a separate server, so if you managed to get hold of the user database you wouldn't necessarily be able to access the passwords.
- yuhong 15y agoAFAIK using simple reversable encryption may prevent a simple SQL injection attack, but of course it won't help if the attacker can gain root on the server, which is much harder though.
- PonyGumbo 15y agoFYI - Hover is a front end for Tucows / OpenSRS, which also store passwords in plain text.
- freejack 15y agoNope, this issue is uniquely ours and has nothing to do with OpenSRS. I usually try not to speak for them, but I can say authoritatively that this simply isn't the case.
- PonyGumbo 15y agoOpenSRS emails both username and password to the administrative address on file when a customer completes the "forgot your password" routine on reseller storefronts.
- bkaid 15y agoNext weeks headline: "Anonymous hacks Hover.com, user database of emails and plain text passwords posted to torrent."
- benbeltran 15y agoFrom reading the post, I think the post says that they'll give users the option to choose if they want their password to be encrypted (and any reset request will contain a URL) or not to be encrypted (and they'll send the plaintext). This way they'll satisfy all users (or so they think.) I hope they default to the secure method.
- drivebyacct2 15y agoOh jeez. I was enjoying the conversation about looking out for dumb users and just giving dumb users what they want. Hover is a domain registrar. I'd rather use GoDaddy than give someone business that tells me that my passwords are stored in plaintext because customers want it. I'd like to login everywhere with just my full name and phone number, are they going to implement that?
- freejack 15y agotl;dr: guy from hover, mea culpa, new code on the way. I thought it might help to provide some further deets on that blog post. I don't think we're making a case there, or providing an excuse - it certainly wasn't my intent to try and convince anyone of anything when I wrote that, but rather, it was an exercise to explain where we were (with that and other development projects) and where we were going. We've gone back and forth on how we handle passwords over the years - and it has always come down to what type of interaction do we think will be best for our customers. I haven't re-read that post from April today, but I think I mentioned our last go-round on this made it much easier for our customers and customer service people to help in bound callers and sacrificed too much in terms of security. We'll probably continue to go back and forth iterating the implementation, each time narrowing the swing of the pendulum until we find something that more appropriately balances what we think our customers are looking for in terms of security and usability. I'd also like to point out that the scope of the risk isn't trivial. For example, URL-based password resets are only as secure as the mailbox they are sent to. i.e. a significant number of domains are stolen and threatened to be stolen through email account exploits (re-registering previously used addresses, forwarding attacks, etc.) This is made even more complex when a domain expires and email on that domain stops functioning. Where should the password reset go? We get dozens and dozens of calls a day from people in this position that need our assistance, making it tough to simply send out a reset request. Anyways, I didn't come here to make excuses, I just thought I should acknowledge that we're aware of the gap (we caused it!) and working on it and considering the whole set of variables. Security is our primary consideration but that doesn't give us the luxury of ignoring the usability implications. Were that the case, we'd simply issue two-factor fobs to our clients and be done with it. And finally, to those of you that guess at some sort of evil corporate motive or the involvement of stupid engineers, or even just dangling the implication that we've "Made a Final Decision" to store passwords this way, etc. It just isn't the case - our engineers are great and our motives are pure. If you want to blame anyone specifically, you can blame me for pushing the implementation in the direction I did. We're really just trying to do the right thing for our clients, and in this case, I took a great idea too far. Its just code, it can be changed - it will be changed, and changed in a way that will help our customer service staff continue to provide awesome customer service and also enhance the protection of our customers assets without stepping on toes in either regard. We originally posted that commentary back in April because we had a ton of work backed up behind the release of our new domain and email management tools - which included a huge refactoring of most of the core code, transitioning to TDD and a ton of other important pieces. We were supposed to be done work on those pieces months ago, but as the management tools took shape, the task grew longer, pushing out these items to the point where it was getting embarrassing with our customers. That work shipped late last month and launches formally tomorrow putting us back in a place where we can get serious about the backlog. The new approach is pretty straightforward and moves us to a hashed password file, URL-based resets, etc. but also some identity verification features that our customers and customer support staff can use to validate who they are talking to in order to force resets manually. Its the validation piece that I'm most excited about given the extent to which the bad guys will go to phish a user out of their creds. We've seen some pretty sophisticated social engineering and we're hoping these new features will give our customers a leg up. Sorry for the lengthy note - happy to take questions, slings, arrows, etc. Ross Rader GM, Hover ross@hover.com
- iamichi 15y agoI emailed a major technology retailer about this when they sent me my password in plaintext. This is the response I got (I pointed out that she made my point for me, but I didn't get another reply)... Dear XXXXXX Thank you for your email dated xx/xx/2011. I apologise for the delay in my response. The only way that people can get your password is to hack into our system or your emails. It has to be sent in plain text for you to know what your password is. I hope this helps. Kind Regards Xxxxx KNOWHOW Customer Support Dixons.co.uk
- mattsidesinger 15y ago"We acknowledge that ours is not the most secure approach." Sounds more eloquent than, "We acknowledge that ours is the least secure approach." Although, the 'smileys' were a nice touch and made me feel more secure.
- Jach 15y agoInteresting use of emoticons in that section. I think we've found a suitable candidate for a first-pass Internet Driver's License test. Filling out a few forgot password forms, checking email, checking spam in case it went there, clicking on a link, and changing to a new password that's >= 10 characters and not a dictionary word...
- NoJoke 15y agoMore QQ. Who cares if I have all your passwords? Get over it.
- damncabbage 15y agohttp://jumba.com.au http://jumba.com.au does this as well; when on the phone to you, they ask you for your password, and the customer support person checks it on their screen. (What could possibly go wrong?)
- swaits 15y agoAre you sure of this? The CSR could also be comparing the hashed/bcrypted/whatever version of the password you give them over the phone to the hashed/bcrypted/whatever version stored in the database.
- damncabbage 15y agoTo activate SSH on your account, you are required to dump your password into the free-text area on a support ticket (see http://support.jumba.com.au/kb/questions/45/Do+you+offer+SSH+access%3F http://support.jumba.com.au/kb/questions/45/Do+you+offer+SSH... ). Given they do this sort of thing, even if they did do fancy hash comparisons when I called them, they still have people's passwords hanging around in plain text elsewhere on the system.
- swaits 15y agoWow, ok. Yah that sounds about as bad as it gets. Stay away!
- LawnGnome 15y agoDepressingly, this seems to be a bit of an Australian thing, as iiNet (and the various ISPs they've bought) are guilty of this too.
- Uchikoma 15y agoIs there a website that lists all services that store plain text passwords? (so one can avoid them)
- boot13 15y agoThis is the closest thing I've found: http://plaintextoffenders.com/ http://plaintextoffenders.com/
- billmcneale 15y ago"Initially, we were emailing reset instructions but people complained that they didn't receive the email. In order to fix this problem, we are now emailing you your password". Makes perfect sense.
- Kwpolska 15y ago"Hover.com: the 'change your password' and 'close account' buttons were removed"
- rowanseymour 15y agoI've given up on trusting any site to protect my password, so now I use passwordmaker.org to create my own hashed site-specific passwords.
- bad_user 15y agoBtw, DreamHost does it too.
- eneveu 15y agoSeems like they listened: http://help.hover.com/2011/07/07/hover-secures-passwords-with-bcrypt-and-enhances-usability-with-identity-verification-tools/ http://help.hover.com/2011/07/07/hover-secures-passwords-wit... Well done, hover!