4 ms·
It would be nice if there existed a browser extension that would warn the user anytime they are about to register on a site with password storage issues like th
by fourk 15y ago
It would be nice if there existed a browser extension that would warn the user anytime they are about to register on a site with password storage issues like this. Of course, there would need to be some sort of community maintained repository for tracking which sites are doing this.
- gst 15y agoWhy should it warn the user? Either the user is using the same password on multiple sites. Then this would be a real security issue, independent of the fact if some of the sites store the password in plaintext. Or the user is using different passwords for different sites. Then you don't really need to care how a single site handles your password.
- fourk 15y agoIf every user used different passwords on every single site, this submission would be hardly newsworthy and barely discussion worthy. In a perfect world, sure, every user would have a unique 14+ character password for every site they register on. In a perfect world, every site would implement basic password encryption. Unfortunately, reality != perfect world.
- axomhacker 15y agoOr... The user usually uses the same password, but seeing this warning and gets alarmed, making him use a different password or not use the service. I love this idea!
- ddlatham 15y agoOne reason is that if they are storing the password in a recoverable format, it tells you something about how much you can trust the security of that site in other ways. Even if you're using a different password, you may be much more hesitant about what other information you are willing to put into a site that doesn't take security seriously.
- srl 15y agoEither the user is using the same password on multiple sites. Then this would be a real security issue, independent of the fact if some of the sites store the password in plaintext. Nevertheless, the vast majority of users do - and that's unlikely to change in the near future. It's just too easy. Many users (the majority? I've seen no statistics for this, but everybody I know falls into this group) do, however, keep several passwords, and assign them to sites based on a combination of 1) how likely the site is to compromise the password (sites that email out plaintext score very poorly) and 2) how much the user cares about the security of that particular account. Which suggests the following use case for fourk's hypothetical plugin: user wants to know what password to use, sees that fooneti.cs is one of those sites that stores easily recoverable passwords, and chooses to use one of the disposable ones.
- dpark 15y agoBecause it's poor security, and the user might care. I don't want to use a site that is so lax about security that they store passwords in plaintext. I don't want them to have any of my information, because they're clearly not competent enough to keep it secure. Whether I'm reusing passwords is irrelevant here. Also, it's a fact that a lot of users reuse passwords. Pretending that it's not the case or claiming that it's the wrong thing to do is pointless. Good security should address the real world, not some silly idealized one.
- pavel_lishin 15y ago> Then you don't really need to care how a single site handles your password. Sure, but if I'm choosing between two sites that offer a similar service, knowing that one is insecure is going to strongly influence me to use the other. It's information that's worth having. Although, this brings up a point - if the list is crowdsourced, companies may have incentives to report their competitors are insecure. There would have to be some way of erasing "insecure!" votes - but then you end up relying on a (hopefully benevolent) dictator. What's a good solution? pg can't be everywhere at once!
- theBobMcCormick 15y agoIf a site is storing their passwords in plain text, it's a good indicator that they are either: A) Incompetent B) Don't give a shit about their users data privacy C) Both of the above.
- joblessjunkie 15y agoIf the site has control over my money or my public persona, then I very much need to care how they handle my password. It is not uncommon for databases to be stolen via lost laptops, human error, or sloppy security. When this happens, I would prefer that the database not contain my plaintext password. If someone obtains my password through such a leak, it won't help me that I've used a distinct password for that website. It's bad news when a bank leaks their customer list. It's catastrophic news when a bank leaks their customer passwords. If you don't store the passwords in the first place, they can't be leaked.
- simonbrown 15y agoThere is one for Chrome. https://chrome.google.com/webstore/detail/ockgeenjbijlgilppfieaklfopnbdpge https://chrome.google.com/webstore/detail/ockgeenjbijlgilppf...