Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 1 of 2 12 LastLast
Results 1 to 10 of 11
  1. #1
    Join Date
    May 2007
    Posts
    10,481
    Tokens
    3,140

    Latest Awards:

    Default Sony needs to employ some cryptographers

    One would expect that they'd at least have started hashing passwords rather than leaving them as plain text...

    In a statement on Thursday, Lulz Security said it had hacked into a database that included unencrypted passwords as well as names, addresses and dates of birth of Sony customers.

    "From a single injection, we accessed EVERYTHING," it said. "Why do you put such faith in a company that allows itself to become open to these simple attacks?"

    "What's worse is that every bit of data we took wasn't encrypted. Sony stored over 1,000,000 passwords of its customers in plain text, which means it's just a matter of taking it.
    http://www.bbc.co.uk/news/business-13636704

    Sony have lost my faith entirely just now, I can understand that they may have slacked before, but if you're trying to improve your security and you're a massive walking target then why would you be dumb enough to keep passwords in plain text? Any person who's worked with a database knows that one of the first things you do with a password is hash it.

    Also BBC need to hire some journalists who know the difference between hashing and encrypting because encrypting the password isn't really solving the problem.
    Last edited by Chippiewill; 03-06-2011 at 01:02 AM.
    Chippiewill.


  2. #2
    Join Date
    May 2005
    Location
    /etc/passwd
    Posts
    19,110
    Tokens
    1,139

    Latest Awards:

    Default

    Quote Originally Posted by Chippiewill View Post
    One would expect that they'd at least have started hashing passwords rather than leaving them as plain text...


    http://www.bbc.co.uk/news/business-13636704

    Sony have lost my faith entirely just now, I can understand that they may have slacked before, but if you're trying to improve your security and you're a massive walking target then why would you be dumb enough to keep passwords in plain text? Any person who's worked with a database knows that one of the first things you do with a password is hash it.

    Also BBC need to hire some journalists who know the difference between hashing and encrypting because encrypting the password isn't really solving the problem.
    Welcome to the world. http://plaintextoffenders.com/
    Quote Originally Posted by Chippiewill View Post
    e-rebel forum moderator
    :8

  3. #3
    Join Date
    Jul 2004
    Location
    California
    Posts
    8,725
    Tokens
    3,789
    Habbo
    HotelUser

    Latest Awards:

    Default

    Poor Sony, is this the evenenth time?
    I'm not crazy, ask my toaster.

  4. #4
    Join Date
    Jun 2005
    Location
    /dev/null
    Posts
    4,918
    Tokens
    126

    Latest Awards:

    Default

    Really bad that large organisations use plaintext.

    It really annoys me when a website emails me the password I created.

  5. #5
    Join Date
    Jun 2008
    Location
    United Kingdom
    Posts
    2,015
    Tokens
    568

    Latest Awards:

    Default

    Quote Originally Posted by N!ck View Post
    Really bad that large organisations use plaintext.

    It really annoys me when a website emails me the password I created.
    Am I the only one that likes being emailed my password when I register on websites? Obviously I always hope that they're emailing it to me, then encrypting/hashing it and storing it in the database. I just like being able to search my emails when I forget a password, rather than having to go through the process of resetting it.

  6. #6
    Join Date
    May 2005
    Location
    /etc/passwd
    Posts
    19,110
    Tokens
    1,139

    Latest Awards:

    Default

    Quote Originally Posted by Trinity View Post
    Am I the only one that likes being emailed my password when I register on websites? Obviously I always hope that they're emailing it to me, then encrypting/hashing it and storing it in the database. I just like being able to search my emails when I forget a password, rather than having to go through the process of resetting it.
    If they're sending you your password in an email, then you can pretty much assume they're either using plaintext or easily reversible encryption
    Quote Originally Posted by Chippiewill View Post
    e-rebel forum moderator
    :8

  7. #7
    Join Date
    Jun 2008
    Location
    United Kingdom
    Posts
    2,015
    Tokens
    568

    Latest Awards:

    Default

    Quote Originally Posted by Recursion View Post
    If they're sending you your password in an email, then you can pretty much assume they're either using plaintext or easily reversible encryption
    Not necessarily. In some of the sites I've made, I set it up to do exactly what I said: user hits register, details get emailed, then encrypted, then stored. I don't do it on every site though, it can cause problems when the email gets sent out but an error stops the info being written to the database. I've just had an awesome idea for how to deal with that though, yay.
    This thread has made me a bit nervous, I might email some of the sites that do send out plain text passwords and ask if they encrypt them afterwards.

  8. #8
    Join Date
    May 2005
    Location
    /etc/passwd
    Posts
    19,110
    Tokens
    1,139

    Latest Awards:

    Default

    Quote Originally Posted by Trinity View Post
    Not necessarily. In some of the sites I've made, I set it up to do exactly what I said: user hits register, details get emailed, then encrypted, then stored. I don't do it on every site though, it can cause problems when the email gets sent out but an error stops the info being written to the database. I've just had an awesome idea for how to deal with that though, yay.
    This thread has made me a bit nervous, I might email some of the sites that do send out plain text passwords and ask if they encrypt them afterwards.
    I meant if you're requesting your password and they send it in plaintext.

    Also, I like the way you do it, but what if someone has a typo in their address and it goes to the wrong person? Their password is then out in the open, which is especially true for people who use the same one for everything.
    Quote Originally Posted by Chippiewill View Post
    e-rebel forum moderator
    :8

  9. #9
    Join Date
    Aug 2004
    Location
    Essex
    Posts
    23,585
    Tokens
    9,258

    Latest Awards:

    Default

    I don't get the point of these people and their attacks:

    "From a single injection, we accessed EVERYTHING," it said. "Why do you put such faith in a company that allows itself to become open to these simple attacks?"

    Isn't that the same as stabbing someone in the face hundreds of times saying "Why did they not put up a fight? Someone else could of done this too and they'll be evil!"

  10. #10
    Join Date
    Jun 2005
    Location
    /dev/null
    Posts
    4,918
    Tokens
    126

    Latest Awards:

    Default

    Quote Originally Posted by Trinity View Post
    Am I the only one that likes being emailed my password when I register on websites? Obviously I always hope that they're emailing it to me, then encrypting/hashing it and storing it in the database. I just like being able to search my emails when I forget a password, rather than having to go through the process of resetting it.
    If they're emailing it to you they have a blatant disregard for security. The only time a password for any worth-while service should traverse the internet in a non-hashed fashion is when you're either logging in or creating the password. Both of which should be done over SSL.

    Although clearly most online banking passwords aren't hashed as they ask for specific letters :S.

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •