Enjoy unlimited access to all forum features for FREE! Optional upgrade available for extra perks.
Domain summit 2024

cctld MyID saving passwords in plain text

Status
Not open for further replies.

katherine

Country hopper
Legacy Exclusive Member
Joined
Jul 9, 2005
Messages
8,428
Reaction score
1,290
Feedback: 65 / 0 / 0
I haven't used MyID for a long time. Today I was disappointed to see that the password reminder feature sends you the actual password on file, instead of a a link to reset your password (which of course, should not be stored in clear but hashed and salted).

:worried:
 

katherine

Country hopper
Legacy Exclusive Member
Joined
Jul 9, 2005
Messages
8,428
Reaction score
1,290
Feedback: 65 / 0 / 0
The Peruvian registry was hacked this week-end. Passwords were saved in SHA1 but unfortunately they were unsalted.
It appears that all of them have been recovered by now. But at least it keeps the hackers busy for a while (a few hours ?).

There is no excuse for poor security like this in 2012.
Again, make sure you don't reuse passwords.
 

msn

Level 8
Legacy Exclusive Member
Joined
Aug 16, 2004
Messages
1,239
Reaction score
36
Feedback: 27 / 0 / 0
Mmmm salty passwords.

We noticed the Peru problem pretty quickly because we started getting spam on our registry account.
 
Status
Not open for further replies.

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Sedo - it.com Premiums

IT.com

Premium Members

AucDom
UKBackorder
Be a Squirrel
MariaBuy

Our Mods' Businesses

URL Shortener
UrlPick.com

*the exceptional businesses of our esteemed moderators

Top Bottom