cancel
Showing results for 
Search instead for 
Did you mean: 

LOS red light on ONT

outcast
Aspiring Champion
Posts: 961
Thanks: 388
Fixes: 19
Registered: ‎11-01-2025

Re: LOS red light on ONT


@geoffday67 wrote:

... if there's a data breach like the co-op etc ...

 

What do you mean "IF" ?, it has already happened multiple times !

On at least four breach events, I personally have had to change passwords and email accounts, directly due to Plusnet leaks.

 

This list appears to cover some of the known breaches, but is missing events like the ACS Law incident.

.

RealAleMadrid
Hero
Posts: 3,093
Thanks: 1,720
Fixes: 66
Registered: ‎07-07-2009

Re: LOS red light on ONT

@geoffday67  I'm not sure why all this password discussion has taken over the thread, the important matter is have you got an Openreach appointment to fix your fibre LOS fault?

Also you should not have needed to enter your username and password in the router, that is assuming you are using a Plusnet supplied Hub. It should configure automatically when your service is activated using the TR-069 Remote Management protocol which on Openreach FTTP uses a dedicated secure VPN channel. At the Plusnet end the router serial number is used to indentify the account and transmit the Username and password to the hub. You could ask Plusnet to check that your hub is set up correctly on the management platform.

Just to recap on the Password question, I have been active on this forum for many years and the security of having to reveal letters of your password has been questioned on occasions. Plusnet say it is secure but will, understandably not give any details. I would tend to agree with @jab1  in post #11. If the system really is insecure I'm sure there would be a lot of forum posts about it.

geoffday67
Hooked
Posts: 8
Registered: ‎23-07-2025

Re: LOS red light on ONT

Wow I had no idea. The ACS Law report talks about sending unencrypted data - that's exactly why I don't want my password stored in a decryptable way. If this kind of incident happens I want to know that the worst that's exposed is a one-way hash of my password.
jab1
The Full Monty
Posts: 22,706
Thanks: 7,927
Fixes: 334
Registered: ‎24-02-2012

Re: LOS red light on ONT


@geoffday67 wrote:
 The ACS Law report talks about sending unencrypted data 

15 years ago - I'm fairly certain that, and other, potential security issues will have been plugged.

John
geoffday67
Hooked
Posts: 8
Registered: ‎23-07-2025

Re: LOS red light on ONT

Storing decryptable passwords is inherently insecure for the reasons highlighted by the ACS case.

The installer didn't say anything about waiting for credentials, hence I fixed it myself.

And yes I do have an engineer appointment for tomorrow so🤞 all will be well again! It's been great to have fibre bandwidth, don't want to come across as just complaining!
jab1
The Full Monty
Posts: 22,706
Thanks: 7,927
Fixes: 334
Registered: ‎24-02-2012

Re: LOS red light on ONT

The ACS Law incident did not say passwords were leaked:

All; Firstly, we would like to apologise again to customers affected by the leak of data from ACS Law. We can confirm that we did send unencrypted data to ACS Law. However, this was not the cause of the leak. At a later date, due to a cyber-attack on the systems of the law firm, data that it held was leaked.

John
jab1
The Full Monty
Posts: 22,706
Thanks: 7,927
Fixes: 334
Registered: ‎24-02-2012

Re: LOS red light on ONT

And this Wiki link clearly shows that ACS:Law were, to put it politely, incompetent.https://en.wikipedia.org/wiki/ACS:Law

 

John
grumble
Aspiring Pro
Posts: 338
Thanks: 53
Registered: ‎15-09-2024

Re: LOS red light on ONT

Obviously a reversible hash (not a one-way hash).