<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dangerous default re rDNS in Plusnet Feedback</title>
    <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952576#M37108</link>
    <description>See what you're saying, but this only happens with static IPs which wouldn't really be used by less IT literate people?&lt;BR /&gt;Just playing devil's advocate rather than trying to say the idea's without merit, we'll make sure it's passed on.</description>
    <pubDate>Tue, 05 Feb 2013 14:15:24 GMT</pubDate>
    <dc:creator>orbrey</dc:creator>
    <dc:date>2013-02-05T14:15:24Z</dc:date>
    <item>
      <title>Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952565#M37097</link>
      <description>I have always known that any site I visit can see my IP address. But I was genuinely appalled a few minutes ago to discover that if they do a Reverse DNS check on that address, it reveals my account username.&lt;BR /&gt;As suggested by Oldjim in reply to &lt;A href="http://community.plus.net/forum/index.php/topic,111476.msg955966.html#msg955966" target="_blank"&gt;this post&lt;/A&gt; I have raised a ticket to stop this.&lt;BR /&gt;&lt;B&gt;Surely &lt;U&gt;the default should be not to reveal this&lt;/U&gt;?&lt;/B&gt; There are only two things preventing a hack, the username and the password, and revealing the first severely compromises the customer's security.&lt;BR /&gt;&lt;SUB&gt;Edit - typo.&lt;/SUB&gt;</description>
      <pubDate>Fri, 01 Feb 2013 18:40:41 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952565#M37097</guid>
      <dc:creator>Estragon</dc:creator>
      <dc:date>2013-02-01T18:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952566#M37098</link>
      <description>Same here...didn't realise that! But I think it's automated when I requested a static IP.</description>
      <pubDate>Fri, 01 Feb 2013 19:58:14 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952566#M37098</guid>
      <dc:creator>AndyH</dc:creator>
      <dc:date>2013-02-01T19:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952567#M37099</link>
      <description>raise a ticket and request a rdns change, you can choose what you want within reason or just have it show your IP address</description>
      <pubDate>Fri, 01 Feb 2013 20:12:33 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952567#M37099</guid>
      <dc:creator>Gus</dc:creator>
      <dc:date>2013-02-01T20:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952568#M37100</link>
      <description>Don't you give away your username if you use your PN email address?</description>
      <pubDate>Fri, 01 Feb 2013 21:08:04 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952568#M37100</guid>
      <dc:creator>itsme</dc:creator>
      <dc:date>2013-02-01T21:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952569#M37101</link>
      <description>I don't even know my Plusnet email address&amp;nbsp; :P.</description>
      <pubDate>Fri, 01 Feb 2013 21:30:42 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952569#M37101</guid>
      <dc:creator>Estragon</dc:creator>
      <dc:date>2013-02-01T21:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952570#M37102</link>
      <description>anything@username.plus.com</description>
      <pubDate>Fri, 01 Feb 2013 21:46:40 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952570#M37102</guid>
      <dc:creator>Gus</dc:creator>
      <dc:date>2013-02-01T21:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952571#M37103</link>
      <description>A good reason not to use it then.</description>
      <pubDate>Fri, 01 Feb 2013 23:07:20 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952571#M37103</guid>
      <dc:creator>Estragon</dc:creator>
      <dc:date>2013-02-01T23:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952572#M37104</link>
      <description>Spotted at TBB - this is the relevant page for requesting a change &lt;A href="https://www.plus.net/wizard/?p=wizard&amp;amp;page=22425&amp;amp;wizard_id=38" target="_blank"&gt;https://www.plus.net/wizard/?p=wizard&amp;amp;page=22425&amp;amp;wizard_id=38&lt;/A&gt;</description>
      <pubDate>Sat, 02 Feb 2013 11:09:16 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952572#M37104</guid>
      <dc:creator>Oldjim</dc:creator>
      <dc:date>2013-02-02T11:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952573#M37105</link>
      <description>Yes, I saw that as well Jim, and your post saying you had posted it here.&lt;BR /&gt;But none of this addresses the basic issue. &lt;U&gt;&lt;B&gt;The default should be to the IP address alone&lt;/B&gt;&lt;/U&gt;, not the account username. It is simply incomprehensible and very insecure for it to be as it is, without even a warning at request time through the Member Centre.</description>
      <pubDate>Sat, 02 Feb 2013 23:22:34 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952573#M37105</guid>
      <dc:creator>Estragon</dc:creator>
      <dc:date>2013-02-02T23:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952574#M37106</link>
      <description>I understand your concern, however nothing at all can be done with a username without its accompanying password. I'm not saying that as an excuse more to belay any belief that it could be seen as a security breach.</description>
      <pubDate>Mon, 04 Feb 2013 10:11:47 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952574#M37106</guid>
      <dc:creator>adamwalker</dc:creator>
      <dc:date>2013-02-04T10:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952575#M37107</link>
      <description>The security of my Plusnet account is protected by two text strings. One is called "username" and the other is called "password". Anyone who knows both can access my account.&lt;BR /&gt;With the current default for rDNS on fixed IPs, I potentially reveal my username to every site I visit on the internet. By definition, that therefore reduces the security of my account, although it doesn't breach it. My account is still protected by the complexity of the password I have chosen. Given what we now know about the poor password practices employed by MOST internet users (who are all human, after all), the revelation of the username is significant. It would be good security practice to eliminate this issue.</description>
      <pubDate>Tue, 05 Feb 2013 09:39:16 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952575#M37107</guid>
      <dc:creator>Bright</dc:creator>
      <dc:date>2013-02-05T09:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952576#M37108</link>
      <description>See what you're saying, but this only happens with static IPs which wouldn't really be used by less IT literate people?&lt;BR /&gt;Just playing devil's advocate rather than trying to say the idea's without merit, we'll make sure it's passed on.</description>
      <pubDate>Tue, 05 Feb 2013 14:15:24 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952576#M37108</guid>
      <dc:creator>orbrey</dc:creator>
      <dc:date>2013-02-05T14:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952577#M37109</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote from: Matt&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;... but this only happens with static IPs which wouldn't really be used by less IT literate people?.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;Even then, IT literate people are unlikely to have a 64-character alphanumeric plus special character password&amp;nbsp; ;). Several may also ask for a static IP address just so they can run the TBB BQM, (which is my only need for one), without really being particularly savvy.&lt;BR /&gt;How many password attempts are allowed before the system locks the account access please Matt?</description>
      <pubDate>Tue, 05 Feb 2013 16:19:38 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952577#M37109</guid>
      <dc:creator>Estragon</dc:creator>
      <dc:date>2013-02-05T16:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952578#M37110</link>
      <description>Sorry for the delay in response. I believe it's ten, and then all attempts are blocked and our networks security team are notified directly.</description>
      <pubDate>Thu, 07 Feb 2013 09:59:55 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952578#M37110</guid>
      <dc:creator>orbrey</dc:creator>
      <dc:date>2013-02-07T09:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952579#M37111</link>
      <description>Not wanting to hijack the thread, but I thought this was relevant. &lt;BR /&gt;Just had reply to a ticket asking for a change to rDNS, have been told that it does not resolve to the ip. However on checking via several sites they all show it resolves to the correct static ip. Come on Plusnet get it right!!!</description>
      <pubDate>Thu, 07 Feb 2013 10:20:39 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952579#M37111</guid>
      <dc:creator>gordonsuk</dc:creator>
      <dc:date>2013-02-07T10:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952580#M37112</link>
      <description>Hi there,&lt;BR /&gt;Really sorry about that - I've fed back to the agent directly and he's picking it up again now. The change should be made for you shortly.</description>
      <pubDate>Thu, 07 Feb 2013 11:20:51 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952580#M37112</guid>
      <dc:creator>orbrey</dc:creator>
      <dc:date>2013-02-07T11:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952581#M37113</link>
      <description>Ah, apologies - the domain may resolve to that IP but you've not got an A record set up which is why the rDNS is failing. If you could get that added via your domain control panel we can get it sorted for you.</description>
      <pubDate>Thu, 07 Feb 2013 11:30:43 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952581#M37113</guid>
      <dc:creator>orbrey</dc:creator>
      <dc:date>2013-02-07T11:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952582#M37114</link>
      <description>Not sure what's going on here. But feel free to check again, have confirmed an A record does exist.&lt;BR /&gt;</description>
      <pubDate>Thu, 07 Feb 2013 11:39:51 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952582#M37114</guid>
      <dc:creator>gordonsuk</dc:creator>
      <dc:date>2013-02-07T11:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952583#M37115</link>
      <description>An A record exists for the root of the domain, the issue is the CNAME record that's pointing mail.domain to the IP the root domain points to. If this is swapped for an A record (as per Bob's response to you on your ticket) we'll be able to make the change for you - though unfortunately we'll need to wait for DNS propagation before it's picked up.&lt;BR /&gt;Hope that helps explain.</description>
      <pubDate>Thu, 07 Feb 2013 11:53:25 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952583#M37115</guid>
      <dc:creator>orbrey</dc:creator>
      <dc:date>2013-02-07T11:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: Dangerous default re rDNS</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952584#M37116</link>
      <description>Thanks guys -Hopefully the update will not take to long.&lt;BR /&gt;</description>
      <pubDate>Thu, 07 Feb 2013 11:59:41 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Dangerous-default-re-rDNS/m-p/952584#M37116</guid>
      <dc:creator>gordonsuk</dc:creator>
      <dc:date>2013-02-07T11:59:41Z</dc:date>
    </item>
  </channel>
</rss>

