• Welcome to DNForum.com - Domain Investor Forum, Free Domain Marketplace and a community for 45+ domain pros
    If you are new to domains and looking to buy, sell and learn about domains then you have come to the right place. DNForum is the oldest global domain name community on the internet and continues to grow every day. There are over 45,000 domainers on DNForum doing everything from buying domains, selling domains, using our free in-house built tools, learning about domains and discussing domains. Take a minute and Register.

customer data including plaintext passwords is currently circulating

Status
Not open for further replies.

mkellerman

New Member
The Originals
Legacy Exclusive Member
Joined
Jul 12, 2004
Messages
376
Reaction score
4
I just received the following e-mail from Sedo which looks genuine


Dear valued SedoPro Customer


We have been informed that due to a security problem at one of our competitors a list of their customer data including plaintext passwords is currently circulating in the domain parking industry and in relevant hacker forums.



Due to the seriousness of this matter combined with the possibility that you might be using the same login data/password at more than one parking company, we strongly advise you to change your password at Sedo.



Sedo uses cryptographically unbreakable ciphertext for password checks and does not store your password in plaintext. This, and a variety of other security measures, ensures that your Sedo account is always safe from third parties.



We generally advise you to always use different login credentials for different sites and never hand out your login credentials to any third party.



Should you have any further questions or needs, your dedicated account manager is looking forward to help.



Kind regards,

Your Sedo Security and Compliance Team
 
I wonder which "competitor" it is?
 
I don't think any would be too bright for any company (or web entity) to keep passwords in plain text format, even Wordpress encrypts the passwords.

The only security risk that this sounds like could be a key logger on the person's computer.

Edit: But it's not a bad idea to follow that advice.
 
I changed mine even though I don't have the same password at more than one place.
Better safe ...
 
Status
Not open for further replies.
Back
Top Bottom