5 ms·
Hey guys, I'm @omervk, one of the co-founders and the maintainer of PTO. Always a pleasure to be featured on the front page of HN. You're welcome to ask me que
by omervk 12y ago
Hey guys, I'm @omervk, one of the co-founders and the maintainer of PTO. Always a pleasure to be featured on the front page of HN.
You're welcome to ask me questions, though we've covered most on our about page (http://plaintextoffenders.com/about http://plaintextoffenders.com/about). The one we haven't is usually "Is there an API/better search/new site coming?" to which the answer is that we're both doing this in our spare time and though we really want to create something better to host this very important content, we can't spare the time. If you've got time and want to volunteer to create this new site, please let me know. :)
- hmemcpy 12y agoHi, I'm @hmemcpy, @omervk's partner in crim^H^H^Hplaintextoffending :) One of Such Volunteers (wow!) made a Chrome Extension that scrapes addresses from PTO and shows you a red banner if you're on a site that's featured PTO! https://chrome.google.com/webstore/detail/plain-text-offenders-aler/ggndaknbenjhnkddgjnjjcmomgaidhmd https://chrome.google.com/webstore/detail/plain-text-offende...
- Springtime 12y agoI suppose the only downside is the list of reformed sites using improved password security appears to rely on user verification and submission, so the list may not always be up to date - but it's certainly better than not knowing at all. Kudos to the extension maker.
- Monkeyget 12y agoApparently the list of offending sites is hardcoded in the extension ( https://github.com/klinskyc/PTOAlert/blob/master/sites.json https://github.com/klinskyc/PTOAlert/blob/master/sites.json ) and the extension is not updated to reflect changes on the sites.
- runn1ng 12y agoYou are also listing websites that send you your password when registering or changing password. I am not sure that's appropriate. I know systems that send you the mail with your password after registration/password change and then save the passwords to database hashed. You cannot deduce that they save passwords in plaintext because they send you the password after registration/password reset. Example: http://plaintextoffenders.com/image/89463394135 http://plaintextoffenders.com/image/89463394135
- omervk 12y agoYes, this is also explained in a link from our About page here: http://plaintextoffenders.com/post/7006690494/whats-so-wrong-about-sending-a-new-password-in http://plaintextoffenders.com/post/7006690494/whats-so-wrong... TL;DR - it's still a security issue (albeit smaller), we've included it in our mandate, please don't do it.
- lyndonh 12y ago> If someone were to hack into any mail account, all they need to do is search for ‘password’ and they have all of the user’s passwords. Only if you're dumb enough to not delete any password emails. Granted, preferable any site sending you your password in an email should either send a reset link or "your password is 'red*'"
- icebraining 12y agoOnly if you're dumb enough to not delete any password emails. You delete it from your MUA, but how can you be sure that it wasn't stored in any of the intermediate servers?
- lyndonh 12y agoThe natural assumption is that the hacker has got your password, not hacked gmail or hotmail, etc.
- deleted 12y ago[deleted]
- oneeyedpigeon 12y agoGreat stuff, although it would be nice to have the list of sites in a more usable format - browsing through individual blog posts looking for a domain isn't particularly efficient. Have you thought about reporting on other aspects of password security, such as misguided length limits or character requirements? Edit: sorry, I guess you've just about covered my first point.
- omervk 12y agoWe've covered length limits before (and entered it into our mandate), since those limits are many times created by placing the password into a fixed-width field in the database.
- aunty_helen 12y agoA couple of simple client-server type graphics would do a lot in explaining why this is an issue to the layman.
- omervk 12y agoThat sounds lovely! Can you help us either in making it or recommending someone who might be able to?
- fooyc 12y agoFor good measure you should list websites allowing you to enter a password on a non-https page, too. That's plain text, too.
- omervk 12y agoWe have a few of those :)
- IbJacked 12y agoNot necessarily. The login page could be http, but as long as it posts to an https address, the password is never transmitted in plain text.
- fooyc 12y agoIf your login page is HTTP, your HTTPS receiver is useless. A MITM can just change the form's target URL in the HTTP login page. On inject any scripts.
- scrollaway 12y agoCool stuff. I was working on a similar site for a while which would give stars to site depending on their various security practices: - HTTPS, HSTS support - Password hashing (and type of hashing if available) - Third party auth support (OpenID/Persona) - 2FA - ... Is this something you would like to go towards? I would love to help (depending on the backend of the site, I may offer technical help too)
- omervk 12y agoOne more very important thing that I neglected to mention is how you can help: - Submit offenders - Spread the word (we're also on Facebook and Twitter (@plntxtoffenders) - Contact offending sites and let them know they're on the list