Enjoy unlimited access to all forum features for FREE! Optional upgrade available for extra perks.
Sedo

For Sale MyID saving passwords in plain text

Status
Not open for further replies.

katherine

Country hopper
Legacy Exclusive Member
Joined
Jul 9, 2005
Messages
8,427
Reaction score
1,290
I haven't used MyID for a long time. Today I was disappointed to see that the password reminder feature sends you the actual password on file, instead of a a link to reset your password (which of course, should not be stored in clear but hashed and salted).

:worried:
 
Dynadot - Expired Domain Auctions

katherine

Country hopper
Legacy Exclusive Member
Joined
Jul 9, 2005
Messages
8,427
Reaction score
1,290
The Peruvian registry was hacked this week-end. Passwords were saved in SHA1 but unfortunately they were unsalted.
It appears that all of them have been recovered by now. But at least it keeps the hackers busy for a while (a few hours ?).

There is no excuse for poor security like this in 2012.
Again, make sure you don't reuse passwords.
 

msn

Level 8
Legacy Exclusive Member
Joined
Aug 16, 2004
Messages
1,239
Reaction score
36
Mmmm salty passwords.

We noticed the Peru problem pretty quickly because we started getting spam on our registry account.
 
Status
Not open for further replies.

Who has viewed this thread (Total: 1) View details

Who has watched this thread (Total: 3) View details

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Members Online

Sedo - it.com Premiums

IT.com

Premium Members

MariaBuy

Upcoming events

New Threads

Our Mods' Businesses

UrlPick.com

*the exceptional businesses of our esteemed moderators

Top Bottom