4 ms·
DreamHost also stores passwords in a recoverable fashion, FYI.
by xorglorb 15y ago
DreamHost also stores passwords in a recoverable fashion, FYI.
- shennyg 15y agoWhich ones? the panel?
- xorglorb 15y agoYes. They will email your password to you if you click the "forgot my password" link.
- pakeha 15y agoARGH! I just confirmed this. So disappointed. I've changed it now to be completely unique but I wouldn't be surprised if it's logged somewhere.
- jrp 15y agoChange the other places you used the old one.
- pavel_lishin 15y agoChange all passwords that are non-unique.
- frankdenbow 15y agoDamn! Confirmed this as well :(
- dsl 15y agoI dropped DreamHost after a week when I called up about an issue and the customer service person wanted me to verify my identity by telling him my password. I explained that I didn't trust him to know my password (assuming he was just typing it into a box), and he said "well its right here in front of me, im just making sure it matches."
- masterzora 15y agoDisclaimer: I am an ex-DH intern and my information is only as good as August 2010, but it is likely to still be accurate. At the very least, DH does not store passwords as plaintext, but it's only very marginally better than that. Passwords are stored using a custom-rolled symmetric encryption algorithm created by... I never found out if it was a founder or just one of the earlier admins, but that doesn't really change much. For what it's worth, I never ran across the key to this, which is at least somewhat good in terms of security, but it's quite possible that this is true only because I never actually went searching for it, especially given that all of the devs and dev interns have root on most of the systems.
- boot13 15y agoI can confirm that they're still doing this. I recently had a conversation with their support staff about it and I don't think they'll be changing it any time soon. I like Dreamhost, but if they don't change this I'll probably bail.
- Dylan16807 15y agoCan you explain why you would leave over that? As long as you are aware of it and use a unique password how does it impact you? They would have to have a very specific and unnoticed breach that gets database and key. Is it worry that they are lax in security elsewhere?
- masterzora 15y agoI'm not one such person (although I've never used DH's services for other reasons, even while I was employed by such), but I could imagine a reasonable person saying "if they take part in bad practice X of which I know, what other bad practices might they take part in of which I don't know?"
- yuhong 15y agoAs I said, it would probably protect against a simple SQL injection, but if the attacker can get root it won't help. Better than nothing, but...