3 ms·
Would you trust a computer security company who didn't hash the passwords of their users on their web site, and instead stored the plain text passwords encrypte
by SimHacker 13y ago
Would you trust a computer security company who didn't hash the passwords of their users on their web site, and instead stored the plain text passwords encrypted in their database, with the keys to decrypt them on their server, because they claim that "Your data are encrypted on our server, if you request the password to be sent to you by email the system knows how to decrypt the information and it will send you the Email. This is for customer convenience as many customer do not wish their password to be reset each time they have a problem."
Would you trust a computer security company that when you reset your password on their web site, sent you a new password that was literally the same as your email address that you signed in with?
If this company sold closed source encryption software, would you trust that the software was competently written and did not have back doors, if the president of the company defended their actions of not hashing passwords, and of resetting passwords to their user's email addresses?
What if the president of that company had been prosecuted for computer crimes in the past, and had spend time in jail for it, because after he was first caught, he went right back to phone freaking again and got caught again?
Would you trust the president of the company, who is a convicted felon, who fraudulently made a lot of money by computer crime and got caught, but had most of the charges dropped and his sentence reduced, not to have made a deal with the government and promise to return their favor of giving him a more lenient sentence in exchange for certain favors in the future?
Can anyone guess who I'm referring to?
- SimHacker 13y agoI'll give you some more hints: His company came out with a "secure" voice encryption product, and then a previously unknown anonymous hacker reviewed the product and its competitors, and wrote a suspiciously positive review of it, claiming it was the only one he couldn't break. His company then published a press release trumpeting the favorable review, right before a big mobile security conference. A suspicious security researcher baited the anonymous hacker to post on his blog, and it turned out he was using an ip addressed registered to the security company whose product he'd written a favorable review about. When confronted with proof, the founder of the security company denied astroturfing, denied knowing the hacker, and implausibly claimed the anonymous hacker must have been using his company's anonymous browsing service. The same security company founder who spent three years in jail for phone phreaking, because he was convicting of hacking and defrauding profit. The same security company who stores their user's passwords in unhashed unsalted plain text encrypted with a key on their server. The same security company who resets their user's passwords with their email address. The same security company whose founder claims that "many customer do not wish their password to be reset each time they have a problem" justifies not hashing passwords, and resetting passwords to "convenient" email addresses. The same security company whose founder refuses to change his "unconventional" security policies after being confronted with these facts, and instead makes ridiculous excuses for his incompetence, and continues to betray the trust of his customers even after he's been confronted with it. Can you figure out who it is now?