<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Customer passwords should NEVER be accessible to support technicians in Plusnet Feedback</title>
    <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220952#M59613</link>
    <description>I was surprised when I was chatting with a support technician earlier today and they asked to confirm certain characters of my password when they were accessing my account. I cannot stress how shockingly insecure this is.&lt;BR /&gt;Firstly, not even considering your support technicians, passwords should always be stored using a one-way hash anyway, which means they are not stored in plain text and the encrypted form cannot be reversed back to their original form.&lt;BR /&gt;Secondly, if they are actually stored using two-way encryption (which is bad enough as it is), allowing your employees to access this information is a huge security risk. Not only does it take one rogue employee to ruin everything, it also creates a large number of entry points for a potential external hacker to gain access to everyone's passwords and everyone's accounts.&lt;BR /&gt;Where does Plusnet stand on this? I've read the same complaint from at least three years ago and still nothing has been done? Seems like it's only going to be a matter of time before your databases are breached and we have another high-profile breach (c.f. Yahoo, Moonpig, Twitch, amongst others).</description>
    <pubDate>Sat, 18 Apr 2015 14:39:22 GMT</pubDate>
    <dc:creator>pg90</dc:creator>
    <dc:date>2015-04-18T14:39:22Z</dc:date>
    <item>
      <title>Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220952#M59613</link>
      <description>I was surprised when I was chatting with a support technician earlier today and they asked to confirm certain characters of my password when they were accessing my account. I cannot stress how shockingly insecure this is.&lt;BR /&gt;Firstly, not even considering your support technicians, passwords should always be stored using a one-way hash anyway, which means they are not stored in plain text and the encrypted form cannot be reversed back to their original form.&lt;BR /&gt;Secondly, if they are actually stored using two-way encryption (which is bad enough as it is), allowing your employees to access this information is a huge security risk. Not only does it take one rogue employee to ruin everything, it also creates a large number of entry points for a potential external hacker to gain access to everyone's passwords and everyone's accounts.&lt;BR /&gt;Where does Plusnet stand on this? I've read the same complaint from at least three years ago and still nothing has been done? Seems like it's only going to be a matter of time before your databases are breached and we have another high-profile breach (c.f. Yahoo, Moonpig, Twitch, amongst others).</description>
      <pubDate>Sat, 18 Apr 2015 14:39:22 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220952#M59613</guid>
      <dc:creator>pg90</dc:creator>
      <dc:date>2015-04-18T14:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220953#M59614</link>
      <description>Surely you could make same point about many institutions you deal with; this is a very common method for many companies.&lt;BR /&gt;The assistant won't have access to the whole p/word.</description>
      <pubDate>Sat, 18 Apr 2015 15:17:25 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220953#M59614</guid>
      <dc:creator>Gel</dc:creator>
      <dc:date>2015-04-18T15:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220954#M59615</link>
      <description>So how exactly would you like your identity to be verified?&lt;BR /&gt;Many banks use a similar method when you contact them to verify that you are who you say you are.</description>
      <pubDate>Sat, 18 Apr 2015 18:21:21 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220954#M59615</guid>
      <dc:creator>gswindale</dc:creator>
      <dc:date>2015-04-18T18:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220955#M59616</link>
      <description>I've contacted tens and tens of companies in the past and absolutely none of them have ever asked for my password or part of it. Most places ask for home address, date of birth etc., or the answer to a "secret question" that you set up when you joined.&lt;BR /&gt;If you think employees from banks will &lt;I&gt;ever&lt;/I&gt; have access to your online password or part of it, you are terribly mistaken.&lt;BR /&gt;adie:quote</description>
      <pubDate>Sat, 18 Apr 2015 18:25:42 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220955#M59616</guid>
      <dc:creator>pg90</dc:creator>
      <dc:date>2015-04-18T18:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220956#M59617</link>
      <description>I've just switched to Natwest Bank and they definitely asked for 3 different letters and numbers of my password to log on their website.&amp;nbsp; I've always been asked that by companies.&amp;nbsp; Never had a problem so far.&amp;nbsp;</description>
      <pubDate>Sat, 18 Apr 2015 19:12:51 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220956#M59617</guid>
      <dc:creator>elkieluca</dc:creator>
      <dc:date>2015-04-18T19:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220957#M59618</link>
      <description>Asked by who? I'm not talking about logging into the website, I'm talking about support technicians and other employees. No Natwest employee is going to ask for anything from your password.&lt;BR /&gt;The difference here is that Plusnet store passwords in (at best) two-way encryption and allow employees access to this information.&lt;BR /&gt;Edit: This is a quote from a Plusnet employee in 2007 (yes, 8 years ago) and it seems practices haven't changed since then:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Customers password are encrypted on our system, in order to pass the data protection checks we need to verify that you are in fact the account holder. So to do this we ask for 2 characters from the password, in order for &lt;B&gt;the CSC agent to see your password&lt;/B&gt; they have to click a link which then leaves an audit trail so we can see who has accessed your password.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;adie:quote</description>
      <pubDate>Sat, 18 Apr 2015 19:14:02 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220957#M59618</guid>
      <dc:creator>pg90</dc:creator>
      <dc:date>2015-04-18T19:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220958#M59619</link>
      <description>Good point I'm thinking of websites.</description>
      <pubDate>Sat, 18 Apr 2015 19:41:51 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220958#M59619</guid>
      <dc:creator>elkieluca</dc:creator>
      <dc:date>2015-04-18T19:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220959#M59620</link>
      <description>They've certainly done it in the past when I've spoken to Lloyds when ringing up to advise I'm going abroad.&lt;BR /&gt;I'm reasonably certain other companies have done the same in the past.&lt;BR /&gt;</description>
      <pubDate>Sat, 18 Apr 2015 20:21:22 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220959#M59620</guid>
      <dc:creator>gswindale</dc:creator>
      <dc:date>2015-04-18T20:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220960#M59621</link>
      <description>One Account ask for random letters from your password and passcode for online and phone security.&amp;nbsp;</description>
      <pubDate>Sat, 18 Apr 2015 21:34:30 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220960#M59621</guid>
      <dc:creator>pwatson</dc:creator>
      <dc:date>2015-04-18T21:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220961#M59622</link>
      <description>I rang a typical large building society recently:&lt;BR /&gt;as well as the usual personal/address confirmation info, they wanted&lt;BR /&gt;1. a certain 2 digits from my password&lt;BR /&gt;2 The full name/place/thing whatever of a particular memorable word.&lt;BR /&gt;</description>
      <pubDate>Sat, 18 Apr 2015 21:39:31 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220961#M59622</guid>
      <dc:creator>x47c</dc:creator>
      <dc:date>2015-04-18T21:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220962#M59623</link>
      <description>The difference (in the cases above) is that the people you're talking to on the phone do not have access to your full password. The people at Plusnet do. Are you really comfortable with that? Would you be comfortable if employees at said banks/building societies had access to your full password?</description>
      <pubDate>Sat, 18 Apr 2015 21:45:40 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220962#M59623</guid>
      <dc:creator>pg90</dc:creator>
      <dc:date>2015-04-18T21:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220963#M59624</link>
      <description>You may well be right, or perhaps PN have changed the system since 2007 and the support agent is now only shown the letters that they ask you for?</description>
      <pubDate>Sat, 18 Apr 2015 21:59:14 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220963#M59624</guid>
      <dc:creator>pwatson</dc:creator>
      <dc:date>2015-04-18T21:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220964#M59625</link>
      <description>If Plusnet have changed their system to what you suggest then that would be better, but still not perfect. It would be nice if someone from Plusnet could confirm either way.</description>
      <pubDate>Sat, 18 Apr 2015 22:00:37 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220964#M59625</guid>
      <dc:creator>pg90</dc:creator>
      <dc:date>2015-04-18T22:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220965#M59626</link>
      <description>Indeed, only PlusNet can say, so you &lt;I&gt;may&lt;/I&gt; be leaping to erroneous conclusions &lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@0FA1396AC0773F33E2DC472BB4F75D3C/images/emoticons/wink.gif" alt="Wink" title="Wink" /&gt;&lt;BR /&gt;Their system may be better still in that the support agent is told which letters to ask for and then told if the answer given was correct?&amp;nbsp; I don't see any difference here to what my bank does...</description>
      <pubDate>Sat, 18 Apr 2015 22:05:16 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220965#M59626</guid>
      <dc:creator>pwatson</dc:creator>
      <dc:date>2015-04-18T22:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220966#M59627</link>
      <description>I accept that I may be jumping to conclusions, however the assumptions are based on:&lt;BR /&gt;1. The support agents have in the past been able to see the full password and there's no evidence that this has changed&lt;BR /&gt;2. Instead of emailing a password reset email, Plusnet are one of the only remaining companies to actually display my password in plaintext when I use the 'forgotten password' link (and that's bad enough on its own!)&lt;BR /&gt;3. Banks have the technology and security to do this properly where Plusnet clearly doesn't (see point 2)&lt;BR /&gt;It's 2015 and using reversible encryption is just asking for trouble. It's a shame that Plusnet will only realise this when they get bitten in the bum by a hacker.</description>
      <pubDate>Sat, 18 Apr 2015 22:51:27 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220966#M59627</guid>
      <dc:creator>pg90</dc:creator>
      <dc:date>2015-04-18T22:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220967#M59628</link>
      <description>Does the OP really think that any operative will note down the two characters for future nefarious use? Chosen randomly by a computer, it's going to nigh impossible to get a full set. Worse i'd think than those played with fuel station vouchers.&lt;BR /&gt;AND I bet the operatives are too &lt;B&gt;busy&lt;/B&gt;.</description>
      <pubDate>Sun, 19 Apr 2015 06:20:55 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220967#M59628</guid>
      <dc:creator>Luzern</dc:creator>
      <dc:date>2015-04-19T06:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220968#M59629</link>
      <description>I'm sure some time ago when I changed my password a PN CS advisor told me when I mentioned it, they can only see the 2 characters they ask me for, not the whole pass word, other than when I told them what password I wanted.</description>
      <pubDate>Sun, 19 Apr 2015 06:40:24 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220968#M59629</guid>
      <dc:creator>Mayfly</dc:creator>
      <dc:date>2015-04-19T06:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220969#M59630</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote from: pg90&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;I've contacted tens and tens of companies in the past and absolutely none of them have ever asked for my password or part of it. Most places ask for home address, date of birth etc., or the answer to a "secret question" that you set up when you joined.&lt;BR /&gt;If you think employees from banks will &lt;I&gt;ever&lt;/I&gt; have access to your online password or part of it, you are terribly mistaken.&lt;BR /&gt;&lt;SPAN style="font-size:8pt"&gt;&lt;SPAN style="color:darkorange;"&gt;[Moderator's note by Adie (dvorak):&amp;nbsp; Full quote of preceding post removed, as per &lt;A href="http://community.plus.net/forum/index.php/topic,132333.0.html" target="_blank"&gt;&lt;B&gt;Forum Rule&lt;/B&gt;&lt;/A&gt;]&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;actually my bank asks for letters.&lt;BR /&gt;the rep cannot see the password.&lt;BR /&gt;what happens is the computer pops up asking for the letter, the rep asks the customer and then enters it, the computer then says if its correct or not.</description>
      <pubDate>Sun, 19 Apr 2015 11:50:33 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220969#M59630</guid>
      <dc:creator>chrcoluk</dc:creator>
      <dc:date>2015-04-19T11:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220970#M59631</link>
      <description>Yes - that is how the Lloyds bank ID checking system works.&lt;BR /&gt;If a faster payment from you is blocked for some reason you get rung up by the bank to check it really is you.&lt;BR /&gt;The bank rep asks you lots of seemingly irrelevant question from your credit report&lt;BR /&gt;These are along the lines of&amp;nbsp; Do you have a credit card with a, b,c or d company etc.&lt;BR /&gt;The rep enters up all the answers.&lt;BR /&gt;At the end their computer says to the rep whether you have passed or failed.&lt;BR /&gt;You are allowed to get some wrong as I certainly have!&lt;BR /&gt;Importantly the bank rep never knows which of the answers you gave were right and which were wrong.&lt;BR /&gt;</description>
      <pubDate>Sun, 19 Apr 2015 12:43:39 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220970#M59631</guid>
      <dc:creator>x47c</dc:creator>
      <dc:date>2015-04-19T12:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: Customer passwords should NEVER be accessible to support technicians</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220971#M59632</link>
      <description>Everyone here seems to be missing the point. This isn't about what banks do, because their systems are entirely different. As I said, banks have the technology installed to allow their support staff to ask for certain bits of account information which their system can verify without their staff ever seeing the complete information.&lt;BR /&gt;Plusnet do not do this. Plusnet support staff can see your entire password (unless someone from Plusnet gets in here and tells me different).&lt;BR /&gt;Here is a quote form James, Plusnet staff, from about a year and a half ago:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;We have to be able to see the full password for troubleshooting issues.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;Find me a bank where their staff can view your online banking password...</description>
      <pubDate>Sun, 19 Apr 2015 13:16:37 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Customer-passwords-should-NEVER-be-accessible-to-support/m-p/1220971#M59632</guid>
      <dc:creator>pg90</dc:creator>
      <dc:date>2015-04-19T13:16:37Z</dc:date>
    </item>
  </channel>
</rss>

