lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <3F56601B.4090000@uchicago.edu>
Date: Wed, 03 Sep 2003 16:41:47 -0500
From: Kim Scarborough <kjs@...icago.edu>
To: bugtraq@...urityfocus.com, full-disclosure@...ts.netsys.com,
   vuln@...unia.com
Subject: Re: SMC Router safe Login in plaintext


> Every ISP I've ever dealt with stores your password in plaintext.  If this 
> were not true, they would not be able to tell you what it is.

I've worked tech support at two ISPs and known many people who have worked at
others. I've never heard of an ISP that stored passwords in plaintext.

> The risk is that someone else could use your account to access the 
> Internet.  Apparently that's a risk the ISPs are willing to take.  So 
> exposing your ISP password in plaintext on your own computer is really no 
> more of a risk than you are already exposed to.

That's a silly thing to say. Even if there are a couple ISPs out there that
store passwords in plaintext, it's hardly the norm, and it's foolish to base
your own habits on that assumption.

-- 
----------------------------------------------------------------------------
Kim Scarborough                                  Web Systems Administrator
University of Chicago/NSIT                       (773) 834-7740
----------------------------------------------------------------------------
Now listening to: Kanuni Garbis - "Ninno Yavrum"
----------------------------------------------------------------------------

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ