4 ms·
I've just signed up and received my confirmation email along with my email and the PASSWORD that I defined. WARNING: These guys use plaintext passwords!! Edit
by makethetick 15y ago
I've just signed up and received my confirmation email along with my email and the PASSWORD that I defined.
WARNING: These guys use plaintext passwords!!
Edit: I received the login info email after I clicked the activation link in a previous email, this means the password must have been stored in a database until I clicked the activation link.
- mootothemax 15y agoI've just signed up and received my confirmation email along with my email and the PASSWORD that I defined. WARNING: These guys use plaintext passwords!! It's not difficult to send a confirmation email that contains your password without having to store your password in plaintext anywhere. Now, I don't know whether they store passwords in plaintext, but it's unfair to make such accusations based on the content of a registration confirmation email. Edit: I received the login info email after I clicked the activation link in a previous email, this means the password must have been stored in a database until I clicked the activation link. Again, there could be a less-than-ideal explanation for this, so we don't know 100% (I was hoping to see a "forgot password" link somewhere to test this with), but this does raise suspicions.
- gzur 15y agoNo, it's not difficult, it's just extremely insecure. Email should always be treated as an insecure channel, so sending passwords over it is just bad security practice. The system should only hang onto the password for as long as it takes to hash it.
- nodata 15y agoWho cares if it's technically possible not to store a password in plain text even though it's in an e-mail? If they're sending passwords in plaintext they're incompetent and not to be trusted, especially for this kind of service. Ouch.
- mootothemax 15y agoWho cares if it's technically possible not to store a password in plain text even though it's in an e-mail? For one, I do. There's a world of difference between handing a http post and storing passwords in the clear in the db. If they're sending passwords in plaintext they're incompetent and not to be trusted, especially for this kind of service. Ouch. I pretty much agree, but stand by my point that sending a password in a confirmation email is the lesser of the two evils.
- dlikhten 15y agoOk for me, storing an encrypted password that is reversible is the same thing as storing a plaintext password. Means that people at least in their company can see my PW. Which means that if I used same PW as my email, they have it. Lets take it a step further... If this is insecure, how much trust can you put that your data is secure? The goal of good online backups is that the only way to actually read data from the backup is to have the user's password. They clearly don't have that as everything is reversible. Dropbox used to claim to be like that, not anymore. Which is why I don't trust dropbox with private data. Instead I store it using AeroFS with local replication.
- nodata 15y agoI don't think he meant that the password is stored in a reversible format. He meant that the e-mail is sent out before the password is encrypted and stored.
- mootothemax 15y agoThanks, this is exactly what I meant :)
- gnufied 15y agoUsually, when you receive your password after signup that does not necessarily mean it is stored in plaintext, because password can be kept in memory through the process. It is warning sign though, agreed.
- makethetick 15y agoI received the login info email after I clicked the activation link in a previous email, this means the password must have been stored in a database until I clicked the activation link. Sorry, should of added that previously.
- mootothemax 15y agoI received the login info email after I clicked the activation link in a previous email, this means the password must have been stored in a database until I clicked the activation link That's not a good sign. The best case scenario I can think of is that the email body is generated at registration and sent out once the activation link is clicked. After this the template is deleted. But it'd be far easier just to store your password in plaintext and go from there. Like you, I'm suspicious.
- baddox 15y agoHonestly, I would rather a site store my password in plain text than send it to me via email. At least if it's stored in plain text, it still requires a security breech to access it. Sending a plain text password via email is no worse than having an insecure (non HTTPS) login form.
- chrischen 15y agoDoesn't necessarily mean they store plain text passwords. Still a bad sign, but they could simply be sending you the email with your password before they hash it.