Full Disclosure mailing list archives

Re: SMC Router safe Login in plaintext


From: "C. Church" <cchurch () alertlogic net>
Date: Wed, 3 Sep 2003 17:14:04 -0500

Every ISP I've ever dealt with stores your password in plaintext.  If
this were not true, they would not be able to tell you what it is.  Just
call support, identify yourself and ask them to change your password for
you.

*shaking head in disbelief*

I've worked for numerous ISPs and not once did _any_ of them ever do
anything as _stupid_ as storing a list of their customers' passwords in
plaintext. (Of course, I'm sure there are a few who lack the foresight to
see the eventual breech of security, but those tend to go out of business
pretty rapidly.)

Did you read what you just said?  How many ISPs have you called where they
would "Tell you what your password is"?  If your ISP can tell you what your
password is, let us know who it is, so we can all avoid them in the future.

Answer: they don't need to know your old password to change your password.
It's called permissions, and privileged access.  As root, or a priveleged
user, I can change anyone's password without having to know the old one.

Think about it.

!c


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: