8 ms·
Passwords in plain text
- bato 12y agoThe scariest part is that there are 200+ pages of those...
- wereHamster 12y agousenetbucket.com Usenet provider Forgot password asks you to type a password, in which it instantly emails back to you in plaintext. Doesn't mean it stores it in plaintext.
- Wouter33 12y agoExactly! That's what i thought. Mailing a password to a user on changing it is maybe not the safest, but it does not mean it saves it plaintext to the database. They can just send out an e-mail when updating the password to the database and then never use the plaintext version anymore.
- pandler 12y agoIt seems that most of these just send you your password as confirmation (or a temp one after requesting password recovery). Even assuming the best case scenario that these are just password confirmation emails, it still bothers me that my password would now be in my email as plaintext.
- Monkeyget 12y agoThe case where you get your new password by mail when you just changed it does not necessarily mean it is stored in plain text. They could keep it around in memory just long enough to send it by mail. Doesn't mean it is a good idea though.
- pjscott 12y agoThere are some ways to do that sort of thing safely, for some value of 'safe', but they're non-trivial. Sticking the plaintext passwords in a database row is trivial. Which do you think is more common? :-(
- zxcdw 12y agoBut that has nothing to do with the fact that just because the site emails you a password doesn't mean that they store the password in plaintext. The catch here is that if they email the password upon the user having entered it (made an account or changed their password, or had password generated for them, ...). If user requests a lost password and it's returned in plaintext, then one can be sure that the password isn't being stored in proper way. HN does this too, by the way. If you request a new password for an account, it's being sent in plaintext. No problem here, what comes to storing it.
- heinrich5991 12y agoNo problem here? It goes through so many servers, unencrypted…
- gpvos 12y agoIt's no problem, as long as it's a one-time-only password and has a limited lifetime (ideally only a day or so). It's similar to a password reset URL, which is also a password equivalent, but only usable once. At least it's better than asking for your mother's maiden name.
- deleted 12y ago[deleted]
- rimantas 12y agoWell, what would you do with an encrypted password sent to you by email? How do you propose to solve this? Using password reset links instead changes very little.
- __david__ 12y ago> Using password reset links instead changes very little. Actually it changes a lot. Password reset links are one time only, and they get sent before you change your password. Mailing your password in plaintext after you've just changed it means it's good even if someone gets a hold of it months or years later. That's significantly worse.
- CiaranMcNulty 12y agoEven if it's not stored at their end in plaintext it's a security issue that it's emailed in plaintext.
- aunty_helen 12y agoThere was an article on HN in the last week (or so) claiming that both inbound and outbound encryption of email was happening. http://readwrite.com/2014/06/06/google-gmail-encryption-fail-comcast#awesm=~oHUqmuxHLxmbAM http://readwrite.com/2014/06/06/google-gmail-encryption-fail... Correct me if I'm wrong but wouldn't this mean that only the email stored on the recipient's email provider's server was then unencrypted.
- gpvos 12y agoIt happens, but way too little.
- jedbrown 12y agoUnfortunately, STARTTLS is subject to service degradation attacks and it is very common for email servers to use unsigned keys. Simply enabling STARTTLS protects against passive attacks, but until email servers refuse connections that do not create a TLS session with proper certs, email will remain subject to MITM attacks. Meanwhile, this failure mode is a usability problem for email. My experience with notifying companies about insecure email practices has been extremely disappointing, even among those that should know better (like national labs and financial institutions).
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- jzelinskie 12y agoScrape all the URLs from that website. Then write a browser extension that looks up the current tab's URL and turns red if it matches one of those domains. Use PRs to manage addition/subtraction of offenders to the list. Now even grandma knows when a website doesn't save your password safely and shaming them will have more impact.
- hhariri 12y agoThere's already a Chrome Extension for it if I'm not mistaken.
- gkcgautam 12y agoCan you share the name or link please?
- rogem002 12y agoI wrote something similar a few months back https://github.com/MikeRogers0/justdelete.me-chrome-extension https://github.com/MikeRogers0/justdelete.me-chrome-extensio... for Just Delete Me, though they offered a nice JSON file for me to use.
- switch007 12y agoFrom a comment further down https://chrome.google.com/webstore/detail/plain-text-offenders-aler/ggndaknbenjhnkddgjnjjcmomgaidhmd https://chrome.google.com/webstore/detail/plain-text-offende...
- borplk 12y agoJust use a unique password every time and rest easy.
- baddox 12y agoThat makes things better, but it's still not great to have your account compromised on one website because that website stored its passwords in plain text.
- omervk 12y ago99.99% of people won't do that. We're trying to make the Internet safer for them.
- aunty_helen 12y agoJust don't get hacked, easy.
- Myrannas 12y agoIts a little scary how big that list is. My concern is that this is a great source of websites with poor security for potential hackers to exploit.
- omervk 12y agoHey guys, I'm @omervk, one of the co-founders and the maintainer of PTO. Always a pleasure to be featured on the front page of HN. You're welcome to ask me questions, though we've covered most on our about page (http://plaintextoffenders.com/about http://plaintextoffenders.com/about). The one we haven't is usually "Is there an API/better search/new site coming?" to which the answer is that we're both doing this in our spare time and though we really want to create something better to host this very important content, we can't spare the time. If you've got time and want to volunteer to create this new site, please let me know. :)
- hmemcpy 12y agoHi, I'm @hmemcpy, @omervk's partner in crim^H^H^Hplaintextoffending :) One of Such Volunteers (wow!) made a Chrome Extension that scrapes addresses from PTO and shows you a red banner if you're on a site that's featured PTO! https://chrome.google.com/webstore/detail/plain-text-offenders-aler/ggndaknbenjhnkddgjnjjcmomgaidhmd https://chrome.google.com/webstore/detail/plain-text-offende...
- Springtime 12y agoI suppose the only downside is the list of reformed sites using improved password security appears to rely on user verification and submission, so the list may not always be up to date - but it's certainly better than not knowing at all. Kudos to the extension maker.
- Monkeyget 12y agoApparently the list of offending sites is hardcoded in the extension ( https://github.com/klinskyc/PTOAlert/blob/master/sites.json https://github.com/klinskyc/PTOAlert/blob/master/sites.json ) and the extension is not updated to reflect changes on the sites.
- runn1ng 12y agoYou are also listing websites that send you your password when registering or changing password. I am not sure that's appropriate. I know systems that send you the mail with your password after registration/password change and then save the passwords to database hashed. You cannot deduce that they save passwords in plaintext because they send you the password after registration/password reset. Example: http://plaintextoffenders.com/image/89463394135 http://plaintextoffenders.com/image/89463394135
- salimane 12y agodigitalocean.com stored your password in plaintext!!!
- jivid 12y agoI am a Digital Ocean customer and the only password they've ever emailed me is the root password for the server I just bought. Arguably this isn't as safe as AWS' process of making you download a kaypair and only letting you login with that. However, VPS owners should get in the habit of logging on to any server they buy and immediately disabling password auth and root login via SSH, which helps negate the root password being sent over email issue to a certain extent.
- TimWolla 12y ago… or even better: Disable password authentication entirely.
- jackalope 12y agoHow is downloading a key pair generated by someone else safer? If this is only for login purposes (I don't use AWS, so maybe there is another reason), you should generate your own key pair and send them only your public key (which doesn't require an encrypted transfer, BTW). If AWS knows your private key and can view it or provide it to you at anytime, that's no different than storing passwords in plaintext.
- jivid 12y agoThe keypair AWS generates can only be downloaded once, at the time of instance creation. Beyond that, they expect you to be in possession of the keypair when launching another instance that uses the same keypair. If you happen to lose the file, you're basically out of luck. So to directly address your concern, you can't download the keypair at any point in time, it's just a one time thing. To me that seems much more secure than emailing out a root password and enabling password authentication by default.
- 12y ago
- vijayaggarwal 12y agoWe already have a fairly good solution to this problem in OAuth. However, current popular implementations of OAuth are third-party owned which is not desirable for many reasons (for example, google won't use facebook owned OAuth, and vice-versa). Ideally, we should have a self-owned OAuth service implemented by browsers or operating systems. And the APIs of this service should be standardized. Also, the storage should be locally available with remote sync optionally available for backup and cross-device syncing.
- Excavator 12y agoSomething like the Firefox Accounts¹ project? Which has Oauth2 support² in the works. 1: https://wiki.mozilla.org/Identity/Firefox_Accounts https://wiki.mozilla.org/Identity/Firefox_Accounts 2: https://github.com/mozilla/fxa-oauth-server https://github.com/mozilla/fxa-oauth-server
- vijayaggarwal 12y agoFxA is primarily for Firefox's own products and services. Mozilla Persona (confusing name - personas is what they called firefox themes as well) is closer.
- Excavator 12y agoYea but there's really no good docs for Persona around anymore, that I can find. The plan is to use Persona for ones FxA: > One we get the basics down and enable single sign-on for relying Mozilla Services with your Firefox Account, we hope integrate Firefox Accounts with Persona on the Web and Firefox user agents to make logging in everywhere as painless as it should be.
- icebraining 12y agoI think that was Microsoft Passport. More recently, it's Mozilla Persona. The problem has always been a lack of incentives for websites to implement them, coupled with user indifference.
- Daiz 12y agoShould really start doing this for sites using MD5/SHA1 for password hashing too, as using them is barely above plain text in terms of security these days.
- TomGullen 12y ago> as using them is barely above plain text in terms of security these days How so?
- watwut 12y agoIf I recall right, those functions are too fast. It is too easy to iterate through all kinds of possible passwords and you are likely to find plenty of matches. At minimum, you need to add unique salt to each password. It forces the attacker to run dictionary on each account separately. It is also recommended to use different slower hash function or iterate MD5/SHA1 thousands times, so he will be much slower.
- jacobparker 12y agoTry to avoid directly invoking "SHA256" in your own security-related code. good: http://en.wikipedia.org/wiki/PBKDF2 http://en.wikipedia.org/wiki/PBKDF2 gooder: http://en.wikipedia.org/wiki/Scrypt http://en.wikipedia.org/wiki/Scrypt Maybe avoid using SHA256 with them because of Bitcoin ASICs. If your passwords get leaked in hashed form, even with these, you'll still want to tell your users and advise/force them to change their passwords. Forcing makes more sense if you have 2FA to something not likely to be accessible with their previous password (SMS maybe?)
- Daiz 12y agoCracking them is so fast these days that they don't offer much in terms of security. For example, take a look at this post: http://www.troyhunt.com/2012/06/our-password-hashing-has-no-clothes.html http://www.troyhunt.com/2012/06/our-password-hashing-has-no-... Then note that it was posted two years ago. GPUs surely haven't gotten any slower since then.
- nly 12y agoUsed a sportsbook a few years ago where the popup to view and update your account details, which had a hidden address bar in most browsers, contained "password=<yourpassword>" in the query string. I reported it but they assured me they were 'using encryption' and to look for the 'lock in my browser'. They were using SSL, but had no clue. The site probably handled millions of $ a week.
- imrehg 12y agoI've been just thinking about this after receiving 2 such emails in one day this week. Submitted both to the archive, thanks so much for doing this! Name and shame, that's the minimum to make them change.
- mrcdima 12y agoBut how does one handle password resets without resorting in one form or another to sending some info in plain text to users? At least one website on the current front page is there because it sent a temporary password in plain text. I assume this happened because the user forgot his password. This says nothing about how they store passwords and after all how else would you handle a password reset? Send a password reset link? That's the same thing. Sending passwords in plaintext back to the user after he has set/changed his password is clearly a security risk but when it comes to temporary passwords or password resets how else would that info be sent?
- p8952 12y agoYou should be sending a token and/or reset link which will allow the user to choose a new password. This is much better than just sending a new password because: * It can have a TTL. * The user has to change it, they can't just keep using the plaintext one forever. * You can perform some kind of verification, was the request for a new password sent from the same country/IP/device as the person generating a new password.
- mrcdima 12y agoBut can't you implement all three with a temporary password as well? Make the password valid for 24 hours only and when the user logs in with their temporary password perform any kind of extra verification and if that's passed then also force the user to change their password. Seems like the same thing. The website I noticed on the front page (sunsuper.com.au) was doing precisely this (although their TTL was 90 days which is indeed far too long and it's impossible to tell whether they forced a password reset or simply recommended a password change).
- jeltz 12y agoYes, but using a token is better for usability and trust since that wont make it possible to lock out other users by clicking the forgot password link, and I as a user will think it is more likely someone doing token based resets has done security correctly.
- drinchev 12y agoAs far as I can remember HN also ( not a long time ago ) was giving plain text passwords. I'm glad this was discontinued and proper recovery password email is sent now. http://i.imgur.com/sDt0DVK.png http://i.imgur.com/sDt0DVK.png
- HarrietJones 12y agoA lot of talk of passwording concentrates on threats at the technology end, and they ignore threats at the user end. Emailed Passwords are a failure from a tech point of view, but they allow users to create more complex passwords without punishing them when they forget that password. As it is, I have situations now when the complexity requirements of a password combined with the fact that I need to sign in to a separate mobile App and I'm given no way of seeing what the password was when I created it that I just throw my metaphorical hands in the air, and reset it to generic password "Green!12Letmein." on yet another account. This is wrong of me. I know it's wrong, I'm aware of password remembering services and I'm technical but I still do it. If I'm doing this, and you're doing this, then most of the world is doing it. By discounting passwords sent through email, then we may be making overall security worse instead of better.
- aianus 12y ago1Password has mobile apps so you can copy and paste passwords on mobile (pretty rare, since most services will remember you). Once you start using it you get really used to it and you won't go back. You just have to force yourself those first few days.
- x1798DE 12y agoThere's no point in using a secure password if it's stored in plaintext. Brute-force attacks on passwords usually need to be done offline in order to be effective (unless the site happens to not throttle authentication queries), so essentially as long as your password isn't one of the attackers' first 100-1000 guesses (being extremely charitable here), then it doesn't matter if your password is 15 characters or 150 characters, because the primary attack vector (database compromise) will reveal it instantly. Additionally, allowing passwords to be e-mailed is even worse than this, because there's a good chance the password is not encrypted in transit, which means that it can be intercepted on the way to your mailbox. In that case, the attacker doesn't even need to compromise the database to get your password, no matter how complex it is. Storing passwords in plaintext removes security even if it makes people use less complicated passwords.
- astazangasta 12y agoWhy are we still doing this? We've known how to do secure authentication without the remote end holding your secret for years via public keys. Everyone here likely does this every day with ssh. There is even a browser mechanism for generating personal certificates for web authentication. The correct long term solution to this ought to be making this solution more intelligible and accessible to users. To hell with passwords and password exchange. They are a huge bug on the internet.
- oakwhiz 12y agoI wish websites would actually use client certificate authentication instead of having to play hot potato with secret passwords.
- ddebernardy 12y agoThis a thousand times. And ssh keys for servers. But then, how would you log into e.g. gmail from a cybercoffee in a foreign country? (Assuming you dare do so in spite of the risk of key loggers.)
- scott_karana 12y ago> But then, how would you log into e.g. gmail from a cybercoffee in a foreign country? (Assuming you dare do so in spite of the risk of key loggers.) This still applies with any other authentication schemes...
- yeukhon 12y agoThe worst is list running mailman that actually sends monthly password reminder. Is the new GNU mailman still shipped with such reminder feature?
- based2 12y agohttp://www.theregister.co.uk/2014/06/20/32000_motherboards_spit_passwords_in_cleartext/ http://www.theregister.co.uk/2014/06/20/32000_motherboards_s...
- golem_de 12y agoI say just mailman. Anyone from Mozilla, EcmaScript, GnuPG and thelike here? Don't miss your monthly "password reminder" mail... P.S. Just save ONLY a salted hash. Hash functions are designed to be one-way, so no one but you can re-store your password. EVER.
- mnemonik 12y agoI filed a bug and it was closed waiting for mailman 3 to ship :-/
- johnsteve 12y agoIt does not seem safe or anything...