4 ms·
Wordpress.com was storing passwords in plain text
Just received this nice email:
-----
Hello,
During an internal audit we noticed that we recorded the password you chose during signup for WordPress.com in plain text. Our policy is to never store plain-text passwords, and we have taken steps to remove the passwords from our systems.
These passwords were stored in a secure location, and there is nothing that suggests they were compromised or the security of your account was decreased in any way. However, out of an abundance of caution we have reset your password.
To reset your password and get access to your account and blog, please follow these steps:
Go to WordPress.com
Click the "Log In" button on the homepage
Click on the link "Lost your password?"
Enter your WordPress.com username:
Click the "Get New Password" button
If you have any further questions or trouble resetting your password, please reply to this message to get help from our support team. We will never ask you to supply your account password or financial information via email.
The WordPress.com Team
-----
Le sigh.
- paulhauggis 12y ago"Le sigh." This doesn't mean it was stored in plain text. There are plenty of 2-way encryption schemes.
- yen223 12y agoUnless wordpress.com doesn't hold the keys for some really odd reason, it might as well have been plaintext.
- bengali3 12y ago"we noticed that we recorded the password you chose during signup for WordPress.com in plain text" agreed, the wording is 'recorded' not stored which makes me lean(naively?) towards something like inadvertent logging for example? ie. plaintext over https through a loadbalancer, with http communication internally, and an internal app logging all its traffic for debugging purposes? then sometime later: oops, we found some log files with plaintext passwords on our servers. IDK, just one scenario that might fall under this description
- otoburb 12y agoI thought your first sentence was sincere, but your last implies otherwise. I don't think everybody received this email. We should be happy that WordPress didn't hide this fact and came clean by informing users. Of course, the email doesn't list when they noticed your password (or other passwords) recorded in plaintext, but at least it's been identified and steps taken to address the problem.
- _zie 12y agoI was admittedly a little heavy handed on the sarcasm (it's been a long day). Absolutely appreciate that they were open and honest about this and that it was discovered during an audit and fixed. Sigh was more that best practices may or may not have been followed up to this point, and there are likely many other companies with similar holes that may not have been as proactive or transparent as WP.
- some_furry 12y agoI really hope the WordPress.com team is using the password_* API provided in PHP 5.5 or by ircmaxell/password_compat for their password storage. That, or scrypt (available in PECL thanks to Dominick Black!)