<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic plusnet still not hashing passwords in Plusnet Feedback</title>
    <link>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204133#M57967</link>
    <description>What is going on, it's 2015 and plusnet are still not salt and hashing passwords. How does that meet with PCI compliance when they hold and process credit card info? I'm extremely disappointed to find Plusnet have still not addressed the serious failing having just been presented my password in the clear having followed the Fogotten My Password link</description>
    <pubDate>Sat, 21 Mar 2015 22:35:19 GMT</pubDate>
    <dc:creator>wfl</dc:creator>
    <dc:date>2015-03-21T22:35:19Z</dc:date>
    <item>
      <title>plusnet still not hashing passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204133#M57967</link>
      <description>What is going on, it's 2015 and plusnet are still not salt and hashing passwords. How does that meet with PCI compliance when they hold and process credit card info? I'm extremely disappointed to find Plusnet have still not addressed the serious failing having just been presented my password in the clear having followed the Fogotten My Password link</description>
      <pubDate>Sat, 21 Mar 2015 22:35:19 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204133#M57967</guid>
      <dc:creator>wfl</dc:creator>
      <dc:date>2015-03-21T22:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: plusnet still not hashing passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204134#M57968</link>
      <description>Interesting. I clicked the Forgotten My Password link and Plusnet sent me a password reminder email.&lt;BR /&gt;When I clicked the link in the email it took me to a page displaying my username and password.&lt;BR /&gt;To be honest I was expecting a password reset email with a link to a page enabling me to chose a different password.</description>
      <pubDate>Sun, 22 Mar 2015 09:51:58 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204134#M57968</guid>
      <dc:creator>Strat</dc:creator>
      <dc:date>2015-03-22T09:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: plusnet still not hashing passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204135#M57969</link>
      <description>probably because when doing a repair to a fault on your broadband the BTOR operative may have to have your password to be able to log in as you</description>
      <pubDate>Mon, 23 Mar 2015 19:40:21 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204135#M57969</guid>
      <dc:creator>x47c</dc:creator>
      <dc:date>2015-03-23T19:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: plusnet still not hashing passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204136#M57970</link>
      <description>No, that's the purpose of the BT test login credentials!</description>
      <pubDate>Mon, 23 Mar 2015 19:56:10 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204136#M57970</guid>
      <dc:creator>pwatson</dc:creator>
      <dc:date>2015-03-23T19:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: plusnet still not hashing passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204137#M57971</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote from: Strat&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;To be honest I was expecting a password reset email with a link to a page enabling me to chose a different password.&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;Great idea - not!&lt;BR /&gt;Would you like to guess how many people would reset their portal password and then find that their broadband connection was dead because the password in the router was wrong? What would make it worse that the broadband would only die when they reconnected which could be many days later so they wouldn't associate the lost connection with the password change.&lt;BR /&gt;Only once Plusnet start using different passwords for the portal and the connection authentication would this be a safe (and very good) suggestion.</description>
      <pubDate>Mon, 23 Mar 2015 20:25:46 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204137#M57971</guid>
      <dc:creator>jelv</dc:creator>
      <dc:date>2015-03-23T20:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: plusnet still not hashing passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204138#M57972</link>
      <description>It's fortunate that Plusnet account passwords don't get compromised then.</description>
      <pubDate>Mon, 23 Mar 2015 20:32:00 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204138#M57972</guid>
      <dc:creator>Strat</dc:creator>
      <dc:date>2015-03-23T20:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: plusnet still not hashing passwords</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204139#M57973</link>
      <description>Now that's a better idea, different passwords for the members area and for your broadband log in. Then the member area password can be properly stored as a hash with no need for anyone to ever be able to read it. And there would be no excuse of engeneers might need it. Then add a proper password reset page.</description>
      <pubDate>Tue, 24 Mar 2015 21:20:39 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/plusnet-still-not-hashing-passwords/m-p/1204139#M57973</guid>
      <dc:creator>wfl</dc:creator>
      <dc:date>2015-03-24T21:20:39Z</dc:date>
    </item>
  </channel>
</rss>

