<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PSN and PN passwords in Plusnet Feedback</title>
    <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788259#M24747</link>
    <description>Hi David, appreciate your point of view,&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote from: David&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; I naturally assume that all passwords which are not internal (for instance, logging into the portal or DSL login details) are encrypted?&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;My understanding of the preceeding statements is that, DSL login details, and portal (as opposed to forum) passwords are one and the same, and unencrypted.&lt;BR /&gt;Having a few years of IT security experience behind me there are many many facets to consider.&amp;nbsp;  For example, if a hacker can hack into the internal network, having the passwords on the internal secure network provides no additional security.&lt;BR /&gt;Next up, as the staff need registered accounts, secure passwords etc, we should consider aspects of their staff joiner, leaver and screening policies, their internal password policy, and the proven or otherwise efficiency of the mechanism used to allow access to the passwords. &amp;nbsp; And more.&amp;nbsp; A good example would be that you'd hope Plusnet are ISO 27002 certified, or at least trying to behave like they are.&lt;BR /&gt;What I think I'm saying is that demonstrating that the passwords are unencrypted yet securely stored, is pretty complex.</description>
    <pubDate>Sun, 01 May 2011 06:46:12 GMT</pubDate>
    <dc:creator>phil4</dc:creator>
    <dc:date>2011-05-01T06:46:12Z</dc:date>
    <item>
      <title>PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788240#M24728</link>
      <description>Hi,&amp;nbsp; the recent debalce over Sony "losing" peoples usernames and passwords leads me to a question that's been niggling in my mind for a while....&lt;BR /&gt;Why do PN support operatives want to know my password when I call up?&amp;nbsp;  This makes me concerned that they can also see my password (thus then using it to check I am who I say I am).&lt;BR /&gt;Login to the portal is protected by SSL so that the password is sent encrypted, so why do the support staff need to see my password?&lt;BR /&gt;Does this therefore mean that once in a hacker would have a trivial time stealing it back?&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Apr 2011 11:56:28 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788240#M24728</guid>
      <dc:creator>phil4</dc:creator>
      <dc:date>2011-04-27T11:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788241#M24729</link>
      <description>We ask&amp;nbsp; for characters from your password as this is a quick and efficient means of performing data protection checks. Also it's important we can see this in case customer's lose or forget their password.&lt;BR /&gt;I'd like to reassure you that passwords are protected and are secure. It's also worth bearing in mind that passwords aren't visible on accounts by default. Agents have access to a link to view the password, this access is logged which means that it's entirely accountable.&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Apr 2011 12:16:12 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788241#M24729</guid>
      <dc:creator>adamwalker</dc:creator>
      <dc:date>2011-04-27T12:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788242#M24730</link>
      <description>I have raised this issue repeatedly, PN believe that being able to access passwords is fine.&lt;BR /&gt;I believe them to be wrong.&lt;BR /&gt;The passwords need to be stored as hashes and totally inaccessible to the staff.&lt;BR /&gt;As far as I am concerned this is a serious security over sight.&lt;BR /&gt;If and when customers forget their passwords, as I'm sure they do, there should be other mechanism for generating new passwords.</description>
      <pubDate>Wed, 27 Apr 2011 12:20:27 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788242#M24730</guid>
      <dc:creator>fourfourdevon</dc:creator>
      <dc:date>2011-04-27T12:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788243#M24731</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;there should be other mechanism for generating new passwords. &lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;What form would you want to see this take if we did this?</description>
      <pubDate>Wed, 27 Apr 2011 12:26:41 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788243#M24731</guid>
      <dc:creator>adamwalker</dc:creator>
      <dc:date>2011-04-27T12:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788244#M24732</link>
      <description>FFD&lt;BR /&gt;It's not just the forgetting of passwords, we need to be able to dial test as customers on occassion and test webspace access, FTP, email etc. Without being able to do this would add a huge support overhead and IMO lead to more annoyed customers that we can't help fully.</description>
      <pubDate>Wed, 27 Apr 2011 12:32:53 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788244#M24732</guid>
      <dc:creator>Chris</dc:creator>
      <dc:date>2011-04-27T12:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788245#M24733</link>
      <description>New passwords sent out by pigeon.&lt;BR /&gt;That way we could have a new password and pigeon stew.&lt;BR /&gt;Or something that only remains valid for 24 hours (after first use) and has to be changed by the user, given over phone/text/pigeon/etc.</description>
      <pubDate>Wed, 27 Apr 2011 12:32:58 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788245#M24733</guid>
      <dc:creator>avatastic</dc:creator>
      <dc:date>2011-04-27T12:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788246#M24734</link>
      <description>I don't believe this practice is uneque to plusnet!&lt;BR /&gt;Every ISP I have been with have asked for my password during calls I have made to them, Mobile phone networks are the same.</description>
      <pubDate>Wed, 27 Apr 2011 12:40:20 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788246#M24734</guid>
      <dc:creator>grudkin</dc:creator>
      <dc:date>2011-04-27T12:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788247#M24735</link>
      <description>Mobile phone networks request a password which is the password for accessing those services (i.e. the password requested is the password for the service you are accessing) the Plusnet password is the password for a whole lot more.&lt;BR /&gt;New passwords could be SMS's, sent by email, or delivered over the phone by CALLING the accounts registered number, or indeed by any means previously confirmed to be a method to contact the subscriber.&lt;BR /&gt;Having worked in tech support myself, I think for the most part "being able to access the users account" is mostly specious, but when it really is needed sometimes, a password reset can be done.</description>
      <pubDate>Wed, 27 Apr 2011 12:56:53 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788247#M24735</guid>
      <dc:creator>fourfourdevon</dc:creator>
      <dc:date>2011-04-27T12:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788248#M24736</link>
      <description>44D - It's required a lot more than you would expect.&lt;BR /&gt;As a very rough guess, in the region of 5-10% of our calls are related to router setup, with a large proportion of those being down to forgotten passwords.&lt;BR /&gt;Whilst I appreciate your feedback and concern, our approach is unlikely to change.</description>
      <pubDate>Wed, 27 Apr 2011 12:59:01 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788248#M24736</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-04-27T12:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788249#M24737</link>
      <description>I thought the routers were self configuring now. Or are those only new/PN supplied ones that do that?</description>
      <pubDate>Wed, 27 Apr 2011 13:00:55 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788249#M24737</guid>
      <dc:creator>avatastic</dc:creator>
      <dc:date>2011-04-27T13:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788250#M24738</link>
      <description>We still get a lot of customers who choose to keep their existing hardware when moving to us from another supplier.&lt;BR /&gt;The majority of our routers do self configure though.&lt;BR /&gt;Then you have the problem with people experiencing difficulties setting up email.&amp;nbsp; We can't then send them an email with their password and not everyone has a mobile.&lt;BR /&gt;I'm pretty comfortable that our approach is fairly normal - as it has been for my previous 3 ISPs.</description>
      <pubDate>Wed, 27 Apr 2011 13:03:44 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788250#M24738</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-04-27T13:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788251#M24739</link>
      <description>or to put another way James if you did not check, I could phone in, give the persons username and do a right screw up of their account, then they would really start SCREAMING</description>
      <pubDate>Wed, 27 Apr 2011 13:08:06 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788251#M24739</guid>
      <dc:creator>pierre_pierre</dc:creator>
      <dc:date>2011-04-27T13:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788252#M24740</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote from: _Adam_Walker_&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;We ask &amp;nbsp;for characters from your password as this is a quick and efficient means of performing data protection checks.&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;Hi, I'd like to confirm this is incorrect, I have experience more than once, your support agents asking for my full password.&lt;BR /&gt;Though it seems the above is pretty irrelevant as you feel it is necessary to allow people access to passwords.&lt;BR /&gt;Just my opinion, but I disagree, and here's a little about why:&lt;BR /&gt;Through my professional experience I've come across scenarios before where people have told me that they "must know" the users passwords to do all manner of things.&lt;BR /&gt;Very easily we changed this, by hashing the passwords, and allowing the support people to reset them when needed. &amp;nbsp;That way no one ever needed to know anyone's password.&lt;BR /&gt;This system is now used by banks big and small, and has been through the SOX process also.&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote from: Jameseh&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;I'm pretty comfortable that our approach is fairly normal - as it has been for my previous 3 ISPs.&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;While it may be "normal" it doesn't mean it's right thing to do.</description>
      <pubDate>Wed, 27 Apr 2011 13:22:37 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788252#M24740</guid>
      <dc:creator>phil4</dc:creator>
      <dc:date>2011-04-27T13:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788253#M24741</link>
      <description>May be worth adding that our support centre staff cannot see your full billing details.</description>
      <pubDate>Wed, 27 Apr 2011 13:51:22 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788253#M24741</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-04-27T13:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788254#M24742</link>
      <description>That's a good thing. &amp;nbsp; Are they stored encrypted? &amp;nbsp;I hope so.&lt;BR /&gt;adie:quote</description>
      <pubDate>Wed, 27 Apr 2011 14:01:06 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788254#M24742</guid>
      <dc:creator>phil4</dc:creator>
      <dc:date>2011-04-27T14:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788255#M24743</link>
      <description>avatastic, &lt;BR /&gt;re the routers they are self configuring but only new ones supplied by ourselves. &lt;BR /&gt;phil4,&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Hi, I'd like to confirm this is incorrect, I have experience more than once, your support agents asking for my full password.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;What I've mentioned is what &lt;B&gt;should&lt;/B&gt; happen, agents should not ask for the full password. So I'll check your account and pass on some feedback if I can spot who did that.&lt;BR /&gt;The official line here is that agents should be asking for two characters (first two/last two/first and last etc).&lt;BR /&gt;Also agents cannot see full billing details. &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Apr 2011 14:16:50 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788255#M24743</guid>
      <dc:creator>adamwalker</dc:creator>
      <dc:date>2011-04-27T14:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788256#M24744</link>
      <description>I think the issue is (if I'm reading it correctly), is it possible for anyone on an outside network (I say possible, not feasible) and obtain peoples usernames and passwords in an unencrypted format or are the passwords inside PN's system on a separate network where even if PN's internal servers were compromised there would be no possible way for the persons doing it to obtain the information?&amp;nbsp; For instance, the link you describe for your staff to view the password, can it only be viewed by an IP address that comes from the internal network and such?</description>
      <pubDate>Sat, 30 Apr 2011 19:26:47 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788256#M24744</guid>
      <dc:creator>David_W</dc:creator>
      <dc:date>2011-04-30T19:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788257#M24745</link>
      <description>It's on a internal. secure network, only staff with registered accounts can log in with their secure passwords or keyfobs.</description>
      <pubDate>Sat, 30 Apr 2011 20:50:06 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788257#M24745</guid>
      <dc:creator>Chris</dc:creator>
      <dc:date>2011-04-30T20:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788258#M24746</link>
      <description>Then I really can't see any issue with PN having the passwords unencrypted as there is no way for them to be taken internally.&amp;nbsp; I naturally assume that all passwords which are not internal (for instance, logging into the portal or DSL login details) are encrypted?</description>
      <pubDate>Sat, 30 Apr 2011 21:26:12 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788258#M24746</guid>
      <dc:creator>David_W</dc:creator>
      <dc:date>2011-04-30T21:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: PSN and PN passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788259#M24747</link>
      <description>Hi David, appreciate your point of view,&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote from: David&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; I naturally assume that all passwords which are not internal (for instance, logging into the portal or DSL login details) are encrypted?&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;My understanding of the preceeding statements is that, DSL login details, and portal (as opposed to forum) passwords are one and the same, and unencrypted.&lt;BR /&gt;Having a few years of IT security experience behind me there are many many facets to consider.&amp;nbsp;  For example, if a hacker can hack into the internal network, having the passwords on the internal secure network provides no additional security.&lt;BR /&gt;Next up, as the staff need registered accounts, secure passwords etc, we should consider aspects of their staff joiner, leaver and screening policies, their internal password policy, and the proven or otherwise efficiency of the mechanism used to allow access to the passwords. &amp;nbsp; And more.&amp;nbsp; A good example would be that you'd hope Plusnet are ISO 27002 certified, or at least trying to behave like they are.&lt;BR /&gt;What I think I'm saying is that demonstrating that the passwords are unencrypted yet securely stored, is pretty complex.</description>
      <pubDate>Sun, 01 May 2011 06:46:12 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PSN-and-PN-passwords/m-p/788259#M24747</guid>
      <dc:creator>phil4</dc:creator>
      <dc:date>2011-05-01T06:46:12Z</dc:date>
    </item>
  </channel>
</rss>

