<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Plusnet Password Security Vulnerability in Plusnet Feedback</title>
    <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Password-Security-Vulnerability/m-p/1883595#M88712</link>
    <description>&lt;P&gt;That's true, I hadn't considered that possibility. Is that what Plusnet claim to do?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems like an odd way of doing things though when there are lots of other security questions that could be asked.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Aug 2022 08:33:48 GMT</pubDate>
    <dc:creator>sdhuk</dc:creator>
    <dc:date>2022-08-15T08:33:48Z</dc:date>
    <item>
      <title>Plusnet Password Security Vulnerability</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Password-Security-Vulnerability/m-p/1883504#M88710</link>
      <description>&lt;P&gt;I was just asked by customer services to give two digits of my password, which means that it must be stored as (or retrievable as) plain text.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no excuse these days for not salting / hashing passwords.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The falls well short of the Information Comissioners Office Guidance on storing passwords now that GPDR is in force:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/security/passwords-in-online-services/" target="_blank" rel="noopener"&gt;https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/security/passwords-in-online-services/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Aug 2022 14:40:50 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Password-Security-Vulnerability/m-p/1883504#M88710</guid>
      <dc:creator>sdhuk</dc:creator>
      <dc:date>2022-08-14T14:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Password Security Vulnerability</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Password-Security-Vulnerability/m-p/1883585#M88711</link>
      <description>Must it?  You sure about that?&lt;BR /&gt;&lt;BR /&gt;It is not impossible for specific two letter combinations to be stored as a hash in isolation from a hash of the whole password.</description>
      <pubDate>Mon, 15 Aug 2022 07:51:27 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Password-Security-Vulnerability/m-p/1883585#M88711</guid>
      <dc:creator>Townman</dc:creator>
      <dc:date>2022-08-15T07:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Password Security Vulnerability</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Password-Security-Vulnerability/m-p/1883595#M88712</link>
      <description>&lt;P&gt;That's true, I hadn't considered that possibility. Is that what Plusnet claim to do?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems like an odd way of doing things though when there are lots of other security questions that could be asked.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 08:33:48 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Password-Security-Vulnerability/m-p/1883595#M88712</guid>
      <dc:creator>sdhuk</dc:creator>
      <dc:date>2022-08-15T08:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Password Security Vulnerability</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Password-Security-Vulnerability/m-p/1883742#M88716</link>
      <description>&lt;P&gt;I do not know what Plusnet does (or does not do) - this issue has been raised before and there have been assurances that full password decryption does not happen.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 22:39:15 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Password-Security-Vulnerability/m-p/1883742#M88716</guid>
      <dc:creator>Townman</dc:creator>
      <dc:date>2022-08-15T22:39:15Z</dc:date>
    </item>
  </channel>
</rss>

