4 ms·
This is pretty bad. I've received password reset emails from dreamhost in the past and the passwords are in plain text...I just renewed two days ago too.
by djenryte 15y ago
This is pretty bad. I've received password reset emails from dreamhost in the past and the passwords are in plain text...I just renewed two days ago too.
- pdkp 15y agoHostgator does this too and don't reset, only resend passwords. It has always bugged me. There is no reason to be storing plain-text, especially for their billing system. At least Dreamhost says the Shell passwords are hashed, which makes sense. I didn't know that about the plain text dreamhost web-panel passwords though.
- ehsanu1 15y agoSurely they don't send you your old password, but a freshly generated one? Then they could still be hashing them after emailing you.
- andfarm 15y agoEmbarrassingly... no. Our login/authentication system was written in 1999, and it shows -- we store panel login passwords using symmetric encryption, and send out the decrypted password when you request it. Getting this fixed was already on our to-do list. This incident has moved it up to near the top of the list (competing with a few other security-related tasks).
- milkmiruku 15y agoI have always been bothered about cpanel passwords coming through in plain text. To confirm, is this the same storage system with mail passwords also? Shell passwords - they're hashed, but are they salted? If not, can they be in future? Thanks for your time.
- jacktoole1 15y agoI've been happy with Dreamhost's service, but becoming aware of this in the last few months has forced me to look into other registrars. If this is fixed, I would be much more inclided to stay. If you could forward these articles to whoever's working on security, I'd appreciate it (and they're a good read): http://www.codinghorror.com/blog/2007/09/rainbow-hash-cracking.html http://www.codinghorror.com/blog/2007/09/rainbow-hash-cracki... http://chargen.matasano.com/chargen/2007/9/7/enough-with-the-rainbow-tables-what-you-need-to-know-about-s.html http://chargen.matasano.com/chargen/2007/9/7/enough-with-the...