Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. E-mailing account information

E-mailing account information

Scheduled Pinned Locked Moved The Lounge
comquestion
25 Posts 11 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P peterchen

    Of course it's not, it means they store passwords in plaintext, or with a reversible encryption (which doesn't provide significant additional safety - leak once, leak all). (And of course, they can send it once at sign up time, but not for recovery. Or the laws of physics might change, or quantum computing might turn out to just work.) (But hey, even HBGary didn't much better)

    FILETIME to time_t
    | FoldWithUs! | sighist | WhoIncludes - Analyzing C++ include file hierarchy

    modified on Wednesday, February 23, 2011 11:25 AM

    D Offline
    D Offline
    Dan Neely
    wrote on last edited by
    #21

    peterchen wrote:

    Of course it's not, it means they store passwords in plaintext, or with a reversible encryption (which doesn't provide significant additional safety - leak once, leak all).

    No it doesn't, they can do that even if they store the password in a hash, by inserting the plaintext into the email before disposing the string which your input was initially stored in.

    3x12=36 2x12=24 1x12=12 0x12=18

    P 1 Reply Last reply
    0
    • J Johnny J

      peterchen wrote:

      how to store the salt?

      In a shaker? ;P

      Gotta run; I've got people to do and things to see...
      -----
      Don't tell my folks I'm a computer programmer - They think I'm a piano player in a cat house...
      -----
      Da mihi sis crustum Etruscum cum omnibus in eo!
      -----
      Everybody is ignorant, only on different subjects - Will Rogers, September 7, 1924

      P Offline
      P Offline
      peterchen
      wrote on last edited by
      #22

      :-D

      FILETIME to time_t
      | FoldWithUs! | sighist | WhoIncludes - Analyzing C++ include file hierarchy

      1 Reply Last reply
      0
      • D Dan Neely

        peterchen wrote:

        Of course it's not, it means they store passwords in plaintext, or with a reversible encryption (which doesn't provide significant additional safety - leak once, leak all).

        No it doesn't, they can do that even if they store the password in a hash, by inserting the plaintext into the email before disposing the string which your input was initially stored in.

        3x12=36 2x12=24 1x12=12 0x12=18

        P Offline
        P Offline
        peterchen
        wrote on last edited by
        #23

        You are a hard-to-please crowd to day. I've updated the post again.

        FILETIME to time_t
        | FoldWithUs! | sighist | WhoIncludes - Analyzing C++ include file hierarchy

        1 Reply Last reply
        0
        • R R tsumami

          Anyone else think its annoying that when you create a account somewhere they mail you your complete account information. I don’t mind that they mail you the information you used to sign up or anything, but do they have to include your password in plain text?

          saru mo ki kara ochiru (even monkeys fall from trees) Usualy i'm that monkey. If you want an intelligent answer, Don't ask me. To understand Recursion, you must first understand Recursion.

          W Offline
          W Offline
          wizardzz
          wrote on last edited by
          #24

          You signed up for one of HBGary's sites?

          1 Reply Last reply
          0
          • E Ennis Ray Lynch Jr

            Not as annoying as slow loading web pages that automatically set focus on the username field causing me to type half of my password in the user name field.

            Need custom software developed? I do custom programming based primarily on MS tools with an emphasis on C# development and consulting. I also do Android Programming as I find it a refreshing break from the MS. "And they, since they Were not the one dead, turned to their affairs" -- Robert Frost

            W Offline
            W Offline
            wizardzz
            wrote on last edited by
            #25

            +5! Especially while someone is sitting next to you watching?

            1 Reply Last reply
            0
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Don't have an account? Register

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • World
            • Users
            • Groups