10 ms·
Major Toronto Utility Company Stores Customers' Passwords in Plain Text
- Swiftdream 2y ago[flagged]
- kurtispatrick9 2y ago[dead]
- vouaobrasil 2y agoGreat. Now all I need is someone to hack my account and pay my electricity bill for me.
- deleted 2y ago[deleted]
- deathanatos 2y agoI think the vector I'd be more worried about here is that someone does a database dump of usernames & passwords, and then proceeds to use that data for credential stuffing. The hygenie of users being on average probably "not great", that would probably lead to subsequent compromise down the line, of things more valuable than the electric company's account. But, IDK, if they're storing passwords in the clear — something so trivial to get right, and so obviously not best practice — I'd also be wondering if the user's bank account routing & account numbers aren't in that same database table…? I can imagine some damage from that.
- _whiteCaps_ 2y agoUtility bills can be used as proof of address for voting. https://www.elections.ca/content.aspx?section=vot&dir=ids&document=index&lang=e https://www.elections.ca/content.aspx?section=vot&dir=ids&do...
- 486sx33 2y agoThis is bad for anyone who recycles passwords. Most everyone I guess. I’m sure they aren’t the only company to do so I don’t think having an online account with your utility provider is required or smart. Good old postal mail is the way.
- pinkmuffinere 2y agoPaying by checks through the mail is so annoying and difficult to stay on top of. I can't understand how you would prefer that approach in general -- is there some strategy here that I'm missing? Or is it that you open mail always immediately when you receive it, and minimize changes in address / vacations? My strategy is to have a "disposable" password that you use for low-value purposes, like paying utilities. I assume this password is public knowledge, and accept that if somebody has it they can do such nefarious things as... pay my utilities bill.
- mikestew 2y agoMy guess as to what OP means: postal mail, as in, mail me my bill. And then pay electronically through your bank, not the company’s online portal. At least that’s the way I do it.
- fragmede 2y agoDo you really want to bank on your utility to have their shit figured out so you don't pay the utility bill for your whole town? Even if you do entirely get it resolved, that seems like extra hassle when you could just... use a password manager.
- pinkmuffinere 2y agoThat’s fair, a password manager would be a good (and likely better) alternative. The only reasons I haven’t made the switch: 1. Even password managers are unreliable, with many popular ones getting hacked in the last 10 years. And I don’t like the idea of storing _all_ my passwords with a single service which may be hacked. I suppose I could just store a subset of my passwords, but that eliminates a lot of the convenience 2. I still find password managers somewhat annoying to use in general. Copy-pasting is disabled on many login forms, so I often would have to manually type an unfamiliar password. And when I’m not using my personal laptop I have to “log in twice” to complete a single intended login - this has historically been fairly common for me, though maybe less common recently
- thrill 2y agoThis should be a criminal offense at this point.
- hooverd 2y agoWho are you prosecuting?
- gleenn 2y agoI believe they're suggesting the people storing the plaintext passwords. Who else would it be?
- hooverd 2y agoI guess there's no one person to hold accountable. They probably just get a small fine and move on.
- Loughla 2y agoWhoever is in charge. That's who you charge. They're the boss. They pay the penalty.
- lotsoweiners 2y agoThey might not know what is being done. They might not even know it is a bad practice. I work in government and you wouldn’t believe how many people are clueless about good practices.
- cs702 2y agoThe thing is probably running on decades-old code that makes common security practices (like storing only salted hashes of passwords) hard. I wouldn't be surprised if there's code in there written in old-style mainframe COBOL or even (gasp) RPG. Sigh.
- CamelCaseName 2y agoToronto Hydro isn't just "a major utility company" It is entirely government owned and the largest electricity provider in the province.
- ojbyrne 2y agoIt’s been a while since I’ve lived in Toronto but I’m pretty sure neither of your points is correct. I believe you’re thinking of Ontario Hydro, though it looks like that’s been privatized and/or split up.
- CamelCaseName 2y agohttps://www.toronto.ca/city-government/accountability-operations-customer-service/city-administration/city-managers-office/agencies-corporations/corporations/toronto-hydro/ https://www.toronto.ca/city-government/accountability-operat... Happy to be corrected though if I'm misreading this!
- ckcheng 2y agoThere was this alleged Alberta AHS privacy breach: https://old.reddit.com/r/alberta/comments/1c7lk3z/ahs_privacy_breach/ https://old.reddit.com/r/alberta/comments/1c7lk3z/ahs_privac... Don’t know if that went anywhere… anyone know?
- Me000 2y agoWhy is this a big deal? Hiring a contractor is 100% more insecure than this. I’m not recommending you do it, but it’s basically just people celebrating they now how to do this, but it’s actually never been exploited once in human history. Yet big brain security people trust contractors to write code and nobody bats an eye.
- er4hn 2y agoThis is an attack called "credential stuffing" and the OWASP page for it has multiple examples of it being used in the real world: https://owasp.org/www-community/attacks/Credential_stuffing https://owasp.org/www-community/attacks/Credential_stuffing .
- hooverd 2y agoI wonder if they in-housed this or paid some external contractor obscene amounts of money for it?
- iinnPP 2y agoThis is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.
- rkagerer 2y agoI've got news for you - they aren't the only ones. Other big companies in the utilities and financial sector also do this, and even some banks. Often it's a product of repeated acquisitions, where the lowest common denominator across disparate systems is some kind of text-based format. That said, I'm surprised a customer service agent ostensibly had access to it. From my own observations (some made during efforts to champion change), industry has gotten better over time. There shouldn't be cases anymore where salted hashes or other alternatives can't be achieved, and I'm pleased to see the public take security and privacy seriously.
- selcuka 2y agoThis is actually more commonplace than you'd think. It doesn't seem to be updated anymore, but there is a web site that listed such services: https://plaintextoffenders.com/ https://plaintextoffenders.com/
- ChrisArchitect 2y agoTitle is: PSA: Toronto Hydro is able to see your login password in plaintext.
- MathMonkeyMan 2y agoI've never designed a system that needed to be secure, nor have I been tasked with breaking one, but... Is plaintext really that much worse than hashed/salted/whatever storage? If the user generated a hard-to-guess password, then the user is also unlikely to reuse it. If the user generated or reused a memorable password, then it would be not too costly to guess most of them using a dictionary attack or whatever the state of the art is for guessing non-random passwords. Is this just defense in depth, or deterrence, or is there something I'm missing that makes the plaintext storage really much more dangerous?
- surfpel 2y agoLook into "rainbow tables" and "salting & peppering" in the context of password storage.
- firen777 2y ago> Is plaintext really that much worse than hashed/salted/whatever storage? Bruh... Any random rouge employee (and judging from OP's post, it's accessible to not just DB admin/IT but also regular supports) can easily scrape any password they want. Considering OP was told the password on a call, I'd guess a low tech social engineer could easily extract any password they want as well. > Is this just defense in depth You use "just" as if "defense in depth" is just some security theater term with no substance.
- MathMonkeyMan 2y agoI say "just" because if I'm missing something fundamental about how passwords are properly stored, then defense in depth might not be the point. I read up a bit more on salting passwords, and now I see that it makes guessing the passwords _way_ harder, because it adds a factor of O(n) to the guessing (n is the number of passwords leaked).
- shaftway 2y agoThe usual plan of attack looks like this: 1. Get a raw dump of a database from 2. Take the usernames and passwords 3. Try logging into eTrade with those usernames and passwords This takes advantage of the fact that a third of people use the same password everywhere [1] and they resist using two factor authentication. You aren't protecting your own site from getting hacked (nobody cares if someone gets the password to your blog comments section), you're protecting your users from themselves. The next step that people will do is hash the password. This makes it much harder to figure out the original password, and it used to be enough. But the problem is that if two people have the same password then their hashes will be the same. Rainbow Tables exploit this problem by doing some pre-work and parallelizing the users being attacked to make the problem space much much smaller. The next step is to add salt to the password hash. Each user gets a few random bytes mixed in with their password before it gets hashed. Now if two users have the same plaintext password their hashes will be different. Rainbow tables don't really work any more because the parallelizing is gone, making the pre-work useless (you could do the pre-work per salt, but that's just as much work as cracking the hash). It's arguable that the next step is using SSO with an identity provider. The downside to this is that you are relying on another company. The upside is that you don't have to store passwords or build the login flow at all. Tradeoffs. 1: https://explodingtopics.com/blog/password-stats https://explodingtopics.com/blog/password-stats
- matttb 2y agoSRP, one of the two major utility services in Phoenix does this as well
- SamuelAdams 2y agoIs Reddit considered a news source now? Half of the posts on the front page are made up fictional writing, and the other half are politics and repeated questions, for the purposes of karma farming. How do we know that the OP of this post did not make these claims up?
- iinnPP 2y agoBased on the wording alone I would believe the OP had thr experience they claim. They just misunderstood what was being asked.
- Stevendonna 2y ago[dead]