<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure Password Storage in Plusnet Feedback</title>
    <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502986#M80061</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/52379"&gt;@FreneticMonk&lt;/a&gt; wrote:&lt;BR /&gt;Or they use the solution I linked to in my OP, but that seems likely not to be the case. I never suggested it was hashed, only that it is best practice. &lt;BR /&gt;&lt;BR /&gt;So everyone is fine with this? Are levels of apathy regarding our personal information really this high?&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I'm happy - so far as I'm aware, PN have only had their password storage hacked once - before I became a member - and at that time, I am given to understand, had some really bright people on board, so I'm guessing there was some effective action taken.&lt;/P&gt;
&lt;P&gt;Just think yourself lucky you're not with TalkTalk, they leak like a colander.&lt;/P&gt;</description>
    <pubDate>Thu, 28 Dec 2017 07:34:09 GMT</pubDate>
    <dc:creator>jab1</dc:creator>
    <dc:date>2017-12-28T07:34:09Z</dc:date>
    <item>
      <title>Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502790#M80053</link>
      <description>&lt;P&gt;I've just spoken to a very friendly person in customer services (great on that front) who asked for two characters of my password. I was a little taken aback since what company does that in 2017?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know how they verify these characters? Presumably they're not held in plaintext since with GDPR coming up they'd be getting a rather hefty fine very soon. I've found one third party blog post which suggests how you could create a secure partial password verification process &lt;A href="https://web.archive.org/web/20160909032102/http://www.smartarchitects.co.uk/news/9/15/Partial-Passwords---How.html" target="_blank"&gt;here&lt;/A&gt;, but with another human doing the verifying over an unsecure phone line there's an obvious flaw to the implementation.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 11:55:57 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502790#M80053</guid>
      <dc:creator>FreneticMonk</dc:creator>
      <dc:date>2017-12-27T11:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502796#M80054</link>
      <description>&lt;P&gt;My energy provider asks for verification info over the phone, at least one other ISP I know does. I do not know, so could be wrong here and I know PN won't confirm or deny (for obvious reasons), but I would imagine the advisor is only presented with the characters they ask you to provide, and not the full data.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 12:23:28 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502796#M80054</guid>
      <dc:creator>jab1</dc:creator>
      <dc:date>2017-12-27T12:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502829#M80055</link>
      <description>&lt;P&gt;I would expect PN to verify my identity, but I don't expect them to ask me to compromise my online account password in the process. Most companies are happy to confirm that they store all passwords as a salted hash, as should be standard, so if PN decline to comment we can only assume the worst case scenario.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't have so much of a problem with customer services seeing part of the password (although this is an issue), but if the data is stored in either plain text or with a reversible encryption method then any data breach would result in more information being exposed than necessary.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 14:04:16 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502829#M80055</guid>
      <dc:creator>FreneticMonk</dc:creator>
      <dc:date>2017-12-27T14:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502972#M80058</link>
      <description>It's not hashed. It can't be, if it was, CS wouldn't have any characters.&lt;BR /&gt;&lt;BR /&gt;It's either encrypted and reversable or just plain text.&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Dec 2017 23:26:00 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502972#M80058</guid>
      <dc:creator>ScottStorey</dc:creator>
      <dc:date>2017-12-27T23:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502977#M80059</link>
      <description>Or they use the solution I linked to in my OP, but that seems likely not to be the case. I never suggested it was hashed, only that it is best practice. &lt;BR /&gt;&lt;BR /&gt;So everyone is fine with this? Are levels of apathy regarding our personal information really this high?</description>
      <pubDate>Thu, 28 Dec 2017 00:43:21 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502977#M80059</guid>
      <dc:creator>FreneticMonk</dc:creator>
      <dc:date>2017-12-28T00:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502978#M80060</link>
      <description>&lt;P&gt;The only way I can see it is:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The passwords are encrypted with something like MD5 - which can be reversed engineered.&lt;/LI&gt;
&lt;LI&gt;Plain text. I'm not being sarcastic&amp;nbsp;but I had an on-line company about 10 years ago had their plain password table hacked and then we were told to change our passwords. Worse case scenario.&lt;/LI&gt;
&lt;LI&gt;The 2 letters are stored in a separate table or field linking to the primary key of the password table. A way I would implement it is to have a trigger to update those fields when the main password field (from the other table) would change. Before encryption&amp;nbsp;has been performed. Produce the two letters then encrypt the whole password into main password table. Then any letter check would have to come from those two fields not the encrypted password table. If you decide to change password via the Portal, then the update coming from there would update&amp;nbsp;the letter check field.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;It could be even better than that, when a new password trigger is activated, get the length of the new one and select two random chararacters and update the checksum database.&lt;/P&gt;
&lt;P&gt;Can't really have more than two though I guess or you can argue it has your whole uncryted password.&amp;nbsp;&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@D10385D46FF09B2E8FF20B0746B65E6F/images/emoticons/shocked.gif" alt="Shocked" title="Shocked" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 00:57:13 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502978#M80060</guid>
      <dc:creator>Alex</dc:creator>
      <dc:date>2017-12-28T00:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502986#M80061</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/52379"&gt;@FreneticMonk&lt;/a&gt; wrote:&lt;BR /&gt;Or they use the solution I linked to in my OP, but that seems likely not to be the case. I never suggested it was hashed, only that it is best practice. &lt;BR /&gt;&lt;BR /&gt;So everyone is fine with this? Are levels of apathy regarding our personal information really this high?&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I'm happy - so far as I'm aware, PN have only had their password storage hacked once - before I became a member - and at that time, I am given to understand, had some really bright people on board, so I'm guessing there was some effective action taken.&lt;/P&gt;
&lt;P&gt;Just think yourself lucky you're not with TalkTalk, they leak like a colander.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 07:34:09 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502986#M80061</guid>
      <dc:creator>jab1</dc:creator>
      <dc:date>2017-12-28T07:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502991#M80062</link>
      <description>&lt;P&gt;password storage wasn't hacked - it was webmail a long time ago &lt;A href="https://community.plus.net/t5/Plusnet-Blogs/Webmail-Incident-Report/ba-p/1313738" target="_blank"&gt;https://community.plus.net/t5/Plusnet-Blogs/Webmail-Incident-Report/ba-p/1313738&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;this post answers the original question &lt;A href="https://community.plus.net/t5/Plusnet-Feedback/Plusnet-password-visible-to-call-centre-staff/m-p/1012452#M42589" target="_blank"&gt;https://community.plus.net/t5/Plusnet-Feedback/Plusnet-password-visible-to-call-centre-staff/m-p/1012452#M42589&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 08:53:37 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502991#M80062</guid>
      <dc:creator>Oldjim</dc:creator>
      <dc:date>2017-12-28T08:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502992#M80063</link>
      <description>&lt;P&gt;Thanks for the correction, &lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/466"&gt;@Oldjim&lt;/a&gt; - as I said, it was before my time here, and Iwasn't aware of the full details. So it wasn't anything really worrying.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 09:00:34 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502992#M80063</guid>
      <dc:creator>jab1</dc:creator>
      <dc:date>2017-12-28T09:00:34Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502994#M80064</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;jab1 wrote:&amp;nbsp;
&lt;P&gt;Just think yourself lucky you're not with TalkTalk, they leak like a colander.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I know&amp;nbsp;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/18089"&gt;@jab1&lt;/a&gt;,&amp;nbsp;it is always concerning (to PlusNet I mean) whether PlusNet will be subject to an attack, being quite a high profile place.&lt;/P&gt;
&lt;P&gt;I've worked for companies who you wouldn't know of, who were worried about the same thing.&lt;/P&gt;
&lt;P&gt;You still get high profile companies hacked. Happened before, and will happen again.&lt;/P&gt;
&lt;P&gt;P.S. On a lighter note, this thread&amp;nbsp;does remind of the Harry Enfield sketch "You don't want to to it like that, you want to do it like this!".&lt;/P&gt;
&lt;P&gt;Let be honest, how many people on here have bumped into people like that. I mean staff and non-staff too.&amp;nbsp;&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@8BBE3DF35B52AAD1B52BEBDC4974E1AD/images/emoticons/tongue.gif" alt="Tongue" title="Tongue" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 09:39:07 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1502994#M80064</guid>
      <dc:creator>Alex</dc:creator>
      <dc:date>2017-12-28T09:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1503670#M80105</link>
      <description>&lt;P&gt;MD5 is not an encryption algorithm, it's a hash function.&lt;/P&gt;
&lt;P&gt;This issue has been raised a few times before.&lt;/P&gt;
&lt;P&gt;The problem probably originates from using the same password to access your account on the Plusnet website and for the PPP connection the router makes. Both ends of the PPP connection need to know the plaintext of the password.&lt;/P&gt;
&lt;P&gt;So before you start considering better ways to store the password, you need to have different passwords for the account and for the PPP connection.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Dec 2017 18:52:10 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1503670#M80105</guid>
      <dc:creator>ejs</dc:creator>
      <dc:date>2017-12-30T18:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536655#M81355</link>
      <description>&lt;P&gt;I called plusnet on this issue back in mid March 2018 (not for the first time)&lt;BR /&gt;I did get an answer.&amp;nbsp; The answer was IMHO the worst case namely the password in the DB is stored as cleartext.&lt;BR /&gt;If you google "GCHQ plusnet password" or simply read &lt;A href="https://www.theregister.co.uk/2015/11/25/plusnet_still_delivering_passwords_plaintext/" target="_blank"&gt;this register article &lt;/A&gt;you will see why I was not surprised&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;1- Of course I immediately changed my password.&lt;BR /&gt;2- I asked plusnet "When will you be encrypting the passwords ?"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; answer : "April the 17th 2018"&lt;BR /&gt;3- On the 19th of April I called back and asked if the passwords were enrypted or not.&amp;nbsp; After the getting past the inevitable irrelevance of "we can only see 2 characters".&amp;nbsp; The answer was "don't know", then on further investigation I was told that they had implemented the encryption of all account passwords on April the 17th 2018.&lt;BR /&gt;This does verify what I was told a month before.&amp;nbsp; Therefore my guess is they have encrypted passwords, although clearly they can be reversed engineered, as they still ask for the 2 characters.&lt;BR /&gt;4- I changed my password once more.&lt;BR /&gt;&lt;BR /&gt;If your password has not been changed since the 17th of April 2018 then in theory you are still vulnerable.&amp;nbsp; Since no one of course knows if your password was read and captured before the 17th.&lt;BR /&gt;So if you are going to play it safe and change the plusnet password then be sure to also change on any email client that may be using the account password by default.&amp;nbsp; And if you have a non-plusnet router you will need to change the plus net account password there also (not to be confused with the router password)&lt;BR /&gt;&lt;BR /&gt;So on a day where twitter have done the right thing still there is no mention or even a hint of plus net customers being recommended to change their passwords.&amp;nbsp; I have asked plus net this twice and they appear to have no plans to inform their customers.&amp;nbsp; Looks like plus net are doing the "Hope Approach".&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 10:02:23 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536655#M81355</guid>
      <dc:creator>malky3200</dc:creator>
      <dc:date>2018-05-04T10:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536663#M81357</link>
      <description>&lt;P&gt;The best course of action in my opinion is to use a separate password for each account you have. With so many on-line accounts requiring passwords it can be a nightmare I know.&lt;/P&gt;
&lt;P&gt;You have no control (not just talking about PlusNet - any company) on how they store it and how secure their platform is.&lt;/P&gt;
&lt;P&gt;So if your PlusNet password were to be hacked, that is it. Only any use there and not elsewhere.&lt;/P&gt;
&lt;P&gt;I keep an Excel sheet of my passwords for each company I use.&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 10:05:40 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536663#M81357</guid>
      <dc:creator>Alex</dc:creator>
      <dc:date>2018-05-04T10:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536682#M81358</link>
      <description>&lt;P&gt;you'd be better using a encrypted password safe program&lt;BR /&gt;an Excel spreadsheet is hardly secure&lt;BR /&gt;plus a password safe/encryption program is very good indeed at generating strong passwords&lt;BR /&gt;in addition they are easier to use as such programs have functions that help with the process in ways that excel cannot&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 11:05:15 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536682#M81358</guid>
      <dc:creator>malky3200</dc:creator>
      <dc:date>2018-05-04T11:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536689#M81359</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/55553"&gt;@malky3200&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I called plusnet on this issue back in mid March 2018 (not for the first time)&lt;BR /&gt;I did get an answer.&amp;nbsp; The answer was IMHO the worst case namely the password in the DB is stored as cleartext.&lt;BR /&gt;If you google "GCHQ plusnet password" or simply read &lt;A href="https://www.theregister.co.uk/2015/11/25/plusnet_still_delivering_passwords_plaintext/" target="_blank"&gt;this register article &lt;/A&gt;you will see why I was not surprised&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I'm sorry that you were misinformed by one of our agents, whilst we generally for security purposes won't comment on our security methods I'm happy to debunk this myth. I'll be really clear but won't for reasons previously stated comment further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We go to great lengths to ensure we protect and secure our customer data. Passwords are, and always have been, encrypted in our database.&lt;/P&gt;
&lt;P&gt;We take the protection of our customers’ data extremely seriously and have a number of robust and resilient measures in place, which we constantly test and review&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 11:25:44 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536689#M81359</guid>
      <dc:creator>JonoH</dc:creator>
      <dc:date>2018-05-04T11:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536725#M81360</link>
      <description>&lt;P&gt;if I was misinformed.... then for the record it was 2 of your agents, several weeks apart.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;In fact one stated the default email is in clear text which would certainly corroborate other reports from users.&lt;/P&gt;
&lt;P&gt;The default email password is of course for many users also the account password.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;So for the record - what was the job that was carried out relating to passwords and encryption on the 17th of April ?&amp;nbsp; Or did both agents get this wrong also ?&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 12:43:40 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536725#M81360</guid>
      <dc:creator>malky3200</dc:creator>
      <dc:date>2018-05-04T12:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536730#M81361</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/55553"&gt;@malky3200&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;if I was misinformed.... then for the record it was 2 of your agents, several weeks apart.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I know, I'm sorry that you were misinformed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;So for the record - what was the job that was carried out relating to passwords and encryption on the 17th of April ?&amp;nbsp; Or did both agents get this wrong also ?&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;It was an improvement to our security practices, that we will not discuss further. Sorry.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 12:50:34 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536730#M81361</guid>
      <dc:creator>JonoH</dc:creator>
      <dc:date>2018-05-04T12:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536793#M81362</link>
      <description>&lt;P&gt;fair enough&lt;/P&gt;
&lt;P&gt;regardless I'm pretty sure I know what it is - As I was told on the phone, more than once&lt;BR /&gt;But I guess we'll never know if that is correct.&amp;nbsp; I'd still change my password for that, for sure.&lt;BR /&gt;&lt;BR /&gt;All I wanted to know at the time was &lt;BR /&gt;1 - do you store the passwords as clear text, I was told yes.&amp;nbsp; (then again I did need to suggest a yes or a no was all that was relevant)&lt;BR /&gt;2 - when will you encrypt them in the DB, the answer of the 17th it now appears is the other reason, which I would not be mentioning either, fair enough.&lt;BR /&gt;&lt;BR /&gt;Did I miss something or does plus net have a statement on this on the web ?&amp;nbsp; I did ask on the calls and I was told no, but worth asking here I guess.&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 13:59:36 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1536793#M81362</guid>
      <dc:creator>malky3200</dc:creator>
      <dc:date>2018-05-04T13:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1538617#M81431</link>
      <description>&lt;P&gt;Came here after chatting with the support to start exactly the same topic only to see that someone already did.&lt;/P&gt;&lt;P&gt;Here is what we know:&lt;/P&gt;&lt;P&gt;- Customer support confirmed that they can check if 2 characters in your password are valid.&lt;/P&gt;&lt;P&gt;- Customer support asks different characters randomly&lt;/P&gt;&lt;P&gt;- After changing your password they can still validate characters in your new password.&lt;/P&gt;&lt;P&gt;- it's technically impossible to check separate letters in a secure, hashed and salted password.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It does not really matter how exactly they store passwords, it might be plaintext or XOR or any other crazy and insecure approach. Regardless, they encryption is reversible and it means that:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Hundreds pf&amp;nbsp;plusnet employees have access to your password&lt;/P&gt;&lt;P&gt;- Support has access to your passwords indirectly - by asking different letter each time they can eventually&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Hackers can steal full password database&lt;/P&gt;&lt;P&gt;- People who use the same password for more than one account(I'd estimate this number at up to 90%) can lose&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Millions, maybe tens of millions users are in a grave danger - they could lose access to &lt;EM&gt;everything&lt;/EM&gt; - their social network accounts, their bank accounts, their email and any service they ever registered with the same account. They are at risk of fraud and identity theft.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's a MASSIVE, INSANE security issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GDPR&amp;nbsp;&lt;SPAN&gt;becomes enforceable on 25 May 2018. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;All companies must guarantee the safety of the user data by then or face quite significant fines.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suggest handing Plusnet GDPR Subject Access Request on that same day and they will have to respond within 30 days.&lt;/P&gt;</description>
      <pubDate>Sun, 13 May 2018 14:19:18 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1538617#M81431</guid>
      <dc:creator>ConcernedUser</dc:creator>
      <dc:date>2018-05-13T14:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Password Storage</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1538627#M81433</link>
      <description>&lt;P&gt;&lt;FONT color="blue"&gt;Moderator's note by Dick (Strat): Post released from Spam Filter.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 13 May 2018 14:49:41 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Secure-Password-Storage/m-p/1538627#M81433</guid>
      <dc:creator>Strat</dc:creator>
      <dc:date>2018-05-13T14:49:41Z</dc:date>
    </item>
  </channel>
</rss>

