Forum Moderators: open

Message Too Old, No Replies

Bad idea for WebmasterWorld to send plain text passwords in email?

         

pbreit

7:07 pm on Jun 16, 2011 (gmt 0)

10+ Year Member



It bugs me that WebmasterWorld emails my password to me in plain text. This is bad style and a not insignificant security issue.

g1smd

9:59 pm on Jun 17, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



It's a personal, private password that I use at other sites.

There's the only problem right there.

Wanna know what the most common passwords are? [youtube.com...] ... at one password per frame, frightening how many seconds it "stuck" on 123456.

lexipixel

10:31 pm on Jun 17, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



It's a personal, private password that I use at other sites.


There's the only problem right there.


exactly. I used think up passwords I could remember with birthdays and initial and hints at what site the password belonged to -- that was AFTER I realized using the same passwords on multiple sites was a bad idea, (forget hackers and email sniffers -- disgruntled insiders / ex-employees are the worst security problem to any site). I also used to keep the passwords relatively short so I could remember them.

Now when I register at a new site I do long random strings with mixed case letters, numbers and punctuation if it's allowed... knowing any decent site will have a "Forgot your passowrd?" feature that will EMAIL me my password, after which I can login and change it again.

REPEAT AFTER ME:
I will not use the same password on multiple sites.
I will not use the same password on multiple sites.
I will not use the same password on multiple sites.

pbreit

10:44 pm on Jun 17, 2011 (gmt 0)

10+ Year Member



You can repeat that all you want but 99% of people don't follow that advice and webmasters should acknowledge that.

jecasc

6:42 am on Jun 18, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



that was AFTER I realized using the same passwords on multiple sites was a bad idea


That's what we are talking about. You first had to REALIZE that this was a bad idea. As did I. Meaning at some point in the past you did use a password on multiple websites. As did I. Until I REALIZED it.

As did every one of us posting here. Hands up if you have ever used the same password on multiple websites in the past. (Raising hand)

Now - it is reasonable to think that there are people out there who have not yet REALIZED this and act accordingly.

If you want to know why storing plaintext passwords as as webmaster is a bad idea go to Google NEWS and type in "plaintext password".

lexipixel

1:00 pm on Jun 18, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



If you want to know why storing plaintext passwords as as webmaster is a bad idea go to Google NEWS and type in "plaintext password".


Note the original post:

It bugs me that WebmasterWorld emails my password to me in plain text. This is bad style and a not insignificant security issue.
-pbreit


Nobody said anything about keeping a plain text list of user's passwords hanging around...

So, now I have to ask the OP;

pbreit, What would you suggest passwords get sent as?

Maybe you'd prefer to have your password embedded into a CAPTCHA style image that is attached to email?

...although those can be sniffed and cracked too.

Or maybe you suggest voice verification for lost password?

...Now there's a real time killer -- maybe Brett can pay someone 24hrs a day to answer the phone because YOU forgot your password -- or had it stolen off one of the other sites where you use the same one, and are now scurrying around changing them all to something else.

How about being forced to fax a copy of your driver's license, and then the password is faxed back?

...again, either requiring a 24 hour person to handle it, or you need to wait until "business hours".

Carrier pigeon?

tangor

3:34 pm on Jun 18, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



As for using the same password on multiple sites... (hand held up) I do... but there's a method to my madness:

low security pws for specific type activity (forums for example), each is a reminder of that activity where there's no personal security exposure. Otherwise, all pws are unique, and hardened.

Then again, there's always the option of just backing off from any site that asks for a pw to participate... after all, one does NOT HAVE TO PARTICIPATE or even come up with a pw.

pbreit

4:27 pm on Jun 18, 2011 (gmt 0)

10+ Year Member



Lexipixel, I was not recovering a password. It was from just registering. None of what you suggest is necessary. Sending a temp password in email is fine (since I both asked for it and it's not mine). Most services send a link to set a new password.

incrediBILL

6:03 pm on Jun 18, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Once upon a time, people were advised to:
#1 Use a different password for each different entity that requires one


I do.

Doesn't everyone?

Not forgetting passwords is a simple mental discipline and the easiest way is to make each password something about the site perhaps plus a special key, some formula you can easily reproduce drunk or sober, but has something special added to thwart simple hacks or stop people from using one password to figure out the others.

Besides, if a plain text password in email gets your knickers in a twist it's because your email is insecure, not the password, secure your email.

koan

8:10 pm on Jun 18, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Nobody said anything about keeping a plain text list of user's passwords hanging around...


If a web site is able to email the password of a user (not a new one randomly generated), it means it isn't hashed in the database. That's what people call "plain text".

pbreit

8:43 pm on Jun 18, 2011 (gmt 0)

10+ Year Member



"Doesn't everyone? "

No. Hardly anyone does.

"If a web site is able to email the password of a user (not a new one randomly generated), it means it isn't hashed in the database"

Not necessarily but there's a good chance. A site could email it in plain text and then encrypted when saving it to the DB.

Again, I didn't mean for this thread to spiral out of control. It was just a simple little observation of what I consider to be a basic security mistake.

However the replies have been eye-opening. There's a surprising amount of confusion. Thinking or suggesting that people use different passwords at different web sites is outlandish as we know almost no one does that.

moTi

11:25 pm on Jun 18, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



the op has a valid point with this issue - but quite a few members think the user is at fault. amazing. do you also put the blame on your customers every time something goes wrong? i seriously wonder how you guys still make your money with that attitude.

tangor

7:48 am on Jun 19, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



...I was not recovering a password. It was from just registering. None of what you suggest is necessary.

Now I'm in the other camp... this was a CONFIRMATION EMAIL that YOUR EMAIL ADDRESS (and selected user name) had been ACCEPTED? No harm, no foul on WW's side, operating on the concept that the email address YOU SENT was secure else you wouldn't know you had been granted access. It was sent plaintext because users are NOT smart enough to deal with encrypted, if they don't have the same encryption software to decode.

If one is REALLY concerned about security then one should NOT use throwaway addresses which have been and can be hacked by the baddies because they are high profile targets, or use systems that are not secured against access by anyone (family, co-workers, company admins, etc.) If this was a SURPRISE, then it indicates you might have problems on YOUR END that others can access your system. If that's not the problem, then what the heck are we talking about?

This is a tempest in a teapot.

pbreit

6:10 pm on Jun 19, 2011 (gmt 0)

10+ Year Member



A password that I have specified should never be sent plain text. Period. That's a very basic security mistake. One problem is that it is sent in plain text on the wire. A bad thing but not a huge concern of mine. Another problem is that it is easily discovered with a quick search on "password" in my email account, an obvious security lapse. Finally, it suggests the password may not be stored correctly by the site owner.

Kudos for you for going from right to wrong.

Why are so many here so security conscious yet don't see the problem? Weird.

Shaddows

3:16 pm on Jun 20, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Putting the onus on the user is shortsighted. Plenty of fledgling members are noobs, looking for advice as they embark on a new hobby that they hope will become a career. Many of them will be content-creators, not "techies" who would be expected to have the rudimentary security consciousness.

I agree with the OP, never send a PW that I just told you back to me. Presumably, if the data capture is efficient, it will have been entered twice to negate the possibility of copy/paste.

Either have a temp PW that you are forced to change on login, or trust that the user remembers it.

Emailing a reset procedure to the registered email will be fine in 99% of user's cases. For the remaining 1%, presumably they are security-conscious enough to use bogus email addresses, and will thus understand and appreciate the irony of being locked out their account due to the site's own commitment to security.

I suppose to counter the "I can't remember what email address I used" objection, you could hide this behind some social prompts, like DOB or name of first pet or something, with a captcha.

I do sympathise with the argument that costs are disproportionate to utilty, and that users employing best practice would negate the need to suffer said costs. However I think the argument that "security is too expensive" is rather weak.

In any case, even if you decide that the status quo is the right balance of Security Vs Utility or Security Vs Cost, it does not mean the OP does not have a point. I find the vociferous nature of the responses to be quite amazing. The current situation might be the best option, but there is no point pretending it's any more than a pragmatic fudge to save costs.
This 44 message thread spans 2 pages: 44