|
Re: Interesting report on TheRegister today
Link doesn't work, probably censored by the forum software blocking part of the title :P
---------- Post added at 15:07 ---------- Previous post was at 15:05 ----------
Haha - found it. The list of blocked words is interesting to say the least, it does contain a lot of offensive/curse words but also blocks obvious words/phrases such as 'abc123' and 'password'
I do wonder how many are blocked by this forum...
Ahem [Edit] Dammit what is it with this forum deleting newlines.
---------- Post added at 15:20 ---------- Previous post was at 15:07 ----------
The reasoning behind it is curious though. At first glance it's implying that it is stored in plaintext and is expected someone may have to read or speak it at some point.
However the plaintext bit is not neccessarily true. Last time I was with VM, passwords were not case sensitive. And according to various forums, VM CSR do routinely ask for your password when telephoning.
In such a scenario, even if it is hashed the above system has merit. Say you phone up and they ask you for your password. They may not be able to see your password, but just enter what you say into a verification system that hashes it and compares it to the stored hash. Thus there's good reason to prevent you having a password of 'fart-rapist-pedo-spaz' in case CSR had to type it in at some point.
And the fact that it's done client side implies the server does not see or store a plaintext password. Although I'm pretty sure telewest have in the past stored plaintext passwords...
|