Membership is FREE – with unlimited access to all features, tools, and discussions. Premium accounts get benefits like banner ads and newsletter exposure. ✅ Signature links are now free for all. 🚫 No AI-generated (LLM) posts allowed. Share your own thoughts and experience — accounts may be terminated for violations.

For Sale MyID saving passwords in plain text

Status
Not open for further replies.

katherine

Country hopper
Legacy Exclusive Member
Joined
Jul 9, 2005
Messages
8,427
Reaction score
1,291
I haven't used MyID for a long time. Today I was disappointed to see that the password reminder feature sends you the actual password on file, instead of a a link to reset your password (which of course, should not be stored in clear but hashed and salted).

:worried:
 

hugegrowth

Level 10
Legacy Exclusive Member
Joined
Mar 28, 2005
Messages
5,992
Reaction score
150
They are upgrading their website right now, so you should contact them with your suggestion.
 

katherine

Country hopper
Legacy Exclusive Member
Joined
Jul 9, 2005
Messages
8,427
Reaction score
1,291
The Peruvian registry was hacked this week-end. Passwords were saved in SHA1 but unfortunately they were unsalted.
It appears that all of them have been recovered by now. But at least it keeps the hackers busy for a while (a few hours ?).

There is no excuse for poor security like this in 2012.
Again, make sure you don't reuse passwords.
 

msn

Level 8
Legacy Exclusive Member
Joined
Aug 16, 2004
Messages
1,239
Reaction score
36
Mmmm salty passwords.

We noticed the Peru problem pretty quickly because we started getting spam on our registry account.
 
Status
Not open for further replies.

Who has viewed this thread (Total: 1) View details

Who has watched this thread (Total: 3) View details

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Members Online

Premium Members

Upcoming events

Our Mods' Businesses

*the exceptional businesses of our esteemed moderators

Top Bottom