<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unencrypted account passwords???  really? in Plusnet Feedback</title>
    <link>https://community.plus.net/t5/Plusnet-Feedback/Unencrypted-account-passwords-really/m-p/1281812#M66852</link>
    <description>&lt;A href="http://www.theregister.co.uk/2015/11/25/plusnet_still_delivering_passwords_plaintext/" target="_blank"&gt;http://www.theregister.co.uk/2015/11/25/plusnet_still_delivering_passwords_plaintext/&lt;/A&gt;&lt;BR /&gt;Please tell me this is not true plusnet &amp;amp; you are not storing passwords in plaintext format &amp;amp; arent using unhashed &amp;amp; unsalted strings as verification ?&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@3681646702FDFD32BCA97E2E5F1BDDD5/images/emoticons/huh.gif" alt="Huh" title="Huh" /&gt;&lt;BR /&gt;Not only that I also hope that the following isnt true, please tell me you arent ignoring the advice of the CESG &amp;amp; other security professionaqls &amp;amp; insisting that 'your way is the best way, because thats how you do it'&amp;nbsp; ?&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@3681646702FDFD32BCA97E2E5F1BDDD5/images/emoticons/huh.gif" alt="Huh" title="Huh" /&gt;&lt;BR /&gt;This is exactly how security breaches happen, in much the same way that your email servers dont use any security either.&amp;nbsp; Are we really supposed to just accept this?&lt;BR /&gt;Given how lapse the security is &amp;amp; the now advertised risk you are presenting to your users, you seem to be painting an awfully big liability target on your back should anyone lose out if your databases of passwords or other information is ever compromised</description>
    <pubDate>Wed, 25 Nov 2015 22:43:39 GMT</pubDate>
    <dc:creator>KitFox</dc:creator>
    <dc:date>2015-11-25T22:43:39Z</dc:date>
    <item>
      <title>Unencrypted account passwords???  really?</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Unencrypted-account-passwords-really/m-p/1281812#M66852</link>
      <description>&lt;A href="http://www.theregister.co.uk/2015/11/25/plusnet_still_delivering_passwords_plaintext/" target="_blank"&gt;http://www.theregister.co.uk/2015/11/25/plusnet_still_delivering_passwords_plaintext/&lt;/A&gt;&lt;BR /&gt;Please tell me this is not true plusnet &amp;amp; you are not storing passwords in plaintext format &amp;amp; arent using unhashed &amp;amp; unsalted strings as verification ?&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@3681646702FDFD32BCA97E2E5F1BDDD5/images/emoticons/huh.gif" alt="Huh" title="Huh" /&gt;&lt;BR /&gt;Not only that I also hope that the following isnt true, please tell me you arent ignoring the advice of the CESG &amp;amp; other security professionaqls &amp;amp; insisting that 'your way is the best way, because thats how you do it'&amp;nbsp; ?&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@3681646702FDFD32BCA97E2E5F1BDDD5/images/emoticons/huh.gif" alt="Huh" title="Huh" /&gt;&lt;BR /&gt;This is exactly how security breaches happen, in much the same way that your email servers dont use any security either.&amp;nbsp; Are we really supposed to just accept this?&lt;BR /&gt;Given how lapse the security is &amp;amp; the now advertised risk you are presenting to your users, you seem to be painting an awfully big liability target on your back should anyone lose out if your databases of passwords or other information is ever compromised</description>
      <pubDate>Wed, 25 Nov 2015 22:43:39 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Unencrypted-account-passwords-really/m-p/1281812#M66852</guid>
      <dc:creator>KitFox</dc:creator>
      <dc:date>2015-11-25T22:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unencrypted account passwords???  really?</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Unencrypted-account-passwords-really/m-p/1281813#M66853</link>
      <description>&lt;B&gt;Moderator Note&lt;/B&gt;&lt;BR /&gt;Locked in favour of &lt;A href="http://community.plus.net/forum/index.php/topic,146131.0.html" target="_blank"&gt;http://community.plus.net/forum/index.php/topic,146131.0.html&lt;/A&gt; on the same subject.</description>
      <pubDate>Wed, 25 Nov 2015 22:46:22 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Unencrypted-account-passwords-really/m-p/1281813#M66853</guid>
      <dc:creator>Strat</dc:creator>
      <dc:date>2015-11-25T22:46:22Z</dc:date>
    </item>
  </channel>
</rss>

