Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Interesting report on TheRegister today

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service
Register FAQ Community Calendar

Interesting report on TheRegister today
Reply
 
Thread Tools
Old 01-09-2014, 15:12   #1
Milambar
Inactive
 
Join Date: Jan 2008
Posts: 954
Milambar has a reputation beyond reputeMilambar has a reputation beyond reputeMilambar has a reputation beyond reputeMilambar has a reputation beyond reputeMilambar has a reputation beyond reputeMilambar has a reputation beyond reputeMilambar has a reputation beyond reputeMilambar has a reputation beyond reputeMilambar has a reputation beyond reputeMilambar has a reputation beyond reputeMilambar has a reputation beyond reputeMilambar has a reputation beyond reputeMilambar has a reputation beyond repute
Interesting report on TheRegister today

Apparently some security company decompiled and audited VM's javascript code on the login pages. Theres a section that not only assesses password strength based on a number of metrics, but also applies a 'bad word' filter to the passwords, not allowing certain words, or words containing certain words.

http://www.theregister.co.uk/2014/09...rom_passwords/

The general consensus for applying any form of wordfilter from a password input is that the passwords are sent and stored in plaintext, and a CSR seeing a defamatory word might get upset.

I tend to agree with this point of view, I can't see any other reason for applying a wordlist filter on the use of 'bad words' on someones password that should be hashed and stored as a monodirectional hash.

Just wondering if anyone here has any comments on this report?
Milambar is offline   Reply With Quote
Advertisement
Old 01-09-2014, 16:20   #2
qasdfdsaq
cf.mega poster
 
Join Date: Aug 2004
Posts: 11,207
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
Re: Interesting report on TheRegister today

Link doesn't work, probably censored by the forum software blocking part of the title :P
---------- Post added at 15:07 ---------- Previous post was at 15:05 ----------

Haha - found it. The list of blocked words is interesting to say the least, it does contain a lot of offensive/curse words but also blocks obvious words/phrases such as 'abc123' and 'password'

I do wonder how many are blocked by this forum...

Ahem [Edit] Dammit what is it with this forum deleting newlines.

---------- Post added at 15:20 ---------- Previous post was at 15:07 ----------

The reasoning behind it is curious though. At first glance it's implying that it is stored in plaintext and is expected someone may have to read or speak it at some point.

However the plaintext bit is not neccessarily true. Last time I was with VM, passwords were not case sensitive. And according to various forums, VM CSR do routinely ask for your password when telephoning.

In such a scenario, even if it is hashed the above system has merit. Say you phone up and they ask you for your password. They may not be able to see your password, but just enter what you say into a verification system that hashes it and compares it to the stored hash. Thus there's good reason to prevent you having a password of 'fart-rapist-pedo-spaz' in case CSR had to type it in at some point.

And the fact that it's done client side implies the server does not see or store a plaintext password. Although I'm pretty sure telewest have in the past stored plaintext passwords...
qasdfdsaq is offline   Reply With Quote
Old 01-09-2014, 17:02   #3
Kushan
cf.mega poster
 
Join Date: Dec 2010
Location: Warrington
Posts: 4,737
Kushan has a bronzed appealKushan has a bronzed appeal
Kushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appeal
Re: Interesting report on TheRegister today

Passwords are stored in plaintext, the agents can see your password on your account. There is no validation beyond what the agent thinks is "valid". If your password is "passw0rd1" and you tell the agent "It's pass word one", the agent might say that's ok or they might not. They should really be more careful than that but it's not a guarantee.

Do note however, your "account" password is not necessarily the same as your email password (which is stored properly and cannot been seen by agents, only reset).
Kushan is offline   Reply With Quote
Old 01-09-2014, 17:06   #4
BenMcr
Inactive
 
Join Date: Nov 2006
Location: Manchester
Services: 360 x2, Maxit TV, Sky Sports and Sky Cinema. Gig1
Posts: 17,929
BenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
BenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
Re: Interesting report on TheRegister today

Just to be clear the article on the The Register is talking about the My VM password, not the telephone account password / challenge.
BenMcr is offline   Reply With Quote
Old 01-09-2014, 17:26   #5
Kushan
cf.mega poster
 
Join Date: Dec 2010
Location: Warrington
Posts: 4,737
Kushan has a bronzed appealKushan has a bronzed appeal
Kushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appeal
Re: Interesting report on TheRegister today

Ben - correct me if I'm wrong (it's been a while since I signed up to VM), but when you sign up for a new account, it asks for a username/password - isn't that the same password that's used on both MyVM and for the account challenge? They can be changed independently afterwards, but during that first signup I am vaguely sure it only asks you for one password.
Kushan is offline   Reply With Quote
Old 01-09-2014, 17:34   #6
BenMcr
Inactive
 
Join Date: Nov 2006
Location: Manchester
Services: 360 x2, Maxit TV, Sky Sports and Sky Cinema. Gig1
Posts: 17,929
BenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
BenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
Re: Interesting report on TheRegister today

Quote:
Originally Posted by Kushan View Post
but when you sign up for a new account, it asks for a username/password - isn't that the same password that's used on both MyVM and for the account challenge?
No, they aren't the same - it asks for the account challenge when you sign up for services on the sales website, but the My VM account isn't created until you either activate broadband (where it's generally required) or choose to do so if you just have TV and / or Telco.
BenMcr is offline   Reply With Quote
Old 01-09-2014, 18:11   #7
DOT COTTON
Permanently Banned
 
Join Date: Aug 2014
Location: albert square
Services: XL TIVO XL PHONE 152MB BB
Posts: 109
DOT COTTON is infamous around these partsDOT COTTON is infamous around these parts
Re: Interesting report on TheRegister today

Quote:
Originally Posted by Kushan View Post
Ben - correct me if I'm wrong (it's been a while since I signed up to VM), but when you sign up for a new account, it asks for a username/password - isn't that the same password that's used on both MyVM and for the account challenge? They can be changed independently afterwards, but during that first signup I am vaguely sure it only asks you for one password.
Could you please change that jumping cat, its bringin on one of me migranes

D
DOT COTTON is offline   Reply With Quote
Old 01-09-2014, 18:37   #8
qasdfdsaq
cf.mega poster
 
Join Date: Aug 2004
Posts: 11,207
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
Re: Interesting report on TheRegister today

Quote:
Originally Posted by DOT COTTON View Post
Could you please change that jumping cat, its bringin on one of me migranes D
But it's a core part of what makes Kushan himself. Changing it would be like changing his entire personality. Please don't.

If you dislike the avatar that much you can just hide or block it.
qasdfdsaq is offline   Reply With Quote
Old 01-09-2014, 20:43   #9
Kushan
cf.mega poster
 
Join Date: Dec 2010
Location: Warrington
Posts: 4,737
Kushan has a bronzed appealKushan has a bronzed appeal
Kushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appeal
Re: Interesting report on TheRegister today

Quote:
Originally Posted by BenMcr View Post
No, they aren't the same - it asks for the account challenge when you sign up for services on the sales website, but the My VM account isn't created until you either activate broadband (where it's generally required) or choose to do so if you just have TV and / or Telco.
Ahh, either it has changed since they revamped the site a few years ago (Would have signed up in about 2008) or I'm just not remembering it correctly, but I do remember thinking that it was odd that the agents could see my password that I used for some things (and don't worry, I've since changed said password and use a password manager these days).

Quote:
Originally Posted by DOT COTTON View Post
Could you please change that jumping cat, its bringin on one of me migranes

D
The last time I tried changing the cat, it clawed my face off. Never again.
Kushan is offline   Reply With Quote
Old 01-09-2014, 21:20   #10
DOT COTTON
Permanently Banned
 
Join Date: Aug 2014
Location: albert square
Services: XL TIVO XL PHONE 152MB BB
Posts: 109
DOT COTTON is infamous around these partsDOT COTTON is infamous around these parts
Re: Interesting report on TheRegister today

Quote:
Originally Posted by Kushan View Post
The last time I tried changing the cat, it clawed my face off. Never again.
Oh I say!
DOT COTTON is offline   Reply With Quote
Old 01-09-2014, 22:31   #11
tweetiepooh
Virgin Media Employee
 
tweetiepooh's Avatar
 
Join Date: Sep 2005
Location: Winchester
Services: Staff MyRates BB: VM 1Gb TV: VM XL Phone : VM XL
Posts: 3,344
tweetiepooh has a bronzed appealtweetiepooh has a bronzed appeal
tweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appeal
Re: Interesting report on TheRegister today

Quote:
Originally Posted by Kushan View Post
The last time I tried changing the cat, it clawed my face off. Never again.
Just show him this if he disagrees.
__________________
I work for VMO2 but reply here in my own right. Any help or advice is made on a best-effort basis. No comments construe any obligation on VMO2 or its employees.
tweetiepooh is offline   Reply With Quote
Old 01-09-2014, 22:39   #12
Skie
a giant headend
 
Join Date: Jan 2011
Location: Liverpool
Posts: 1,169
Skie has reached the bronze age
Skie has reached the bronze ageSkie has reached the bronze ageSkie has reached the bronze ageSkie has reached the bronze ageSkie has reached the bronze ageSkie has reached the bronze ageSkie has reached the bronze age
Re: Interesting report on TheRegister today

Back when myVM was overhauled a few of us raised concerns about the password requirements, they do seem pretty weird and some of them are hardly best practice when it comes to security.
Skie is offline   Reply With Quote
Old 02-09-2014, 14:29   #13
tweetiepooh
Virgin Media Employee
 
tweetiepooh's Avatar
 
Join Date: Sep 2005
Location: Winchester
Services: Staff MyRates BB: VM 1Gb TV: VM XL Phone : VM XL
Posts: 3,344
tweetiepooh has a bronzed appealtweetiepooh has a bronzed appeal
tweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appeal
Re: Interesting report on TheRegister today

I hate restrictive password rules, some are sensible but if too strict either people will write them down or you end up with lots of calls about password issues. This is especially true where password changes are enforced.

I use LastPass to generate passwords for lots of sites (not banking, no connection for these) so I don't know what they are, just random set of letters, numbers, symbols. Other tools also offer the same sort of function.
__________________
I work for VMO2 but reply here in my own right. Any help or advice is made on a best-effort basis. No comments construe any obligation on VMO2 or its employees.
tweetiepooh is offline   Reply With Quote
Old 02-09-2014, 14:32   #14
Kushan
cf.mega poster
 
Join Date: Dec 2010
Location: Warrington
Posts: 4,737
Kushan has a bronzed appealKushan has a bronzed appeal
Kushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appealKushan has a bronzed appeal
Re: Interesting report on TheRegister today

I also use lastpass, absolutely love it. Made out like a bandit recently with their 12month + 6month subscription giveaway, before they nuked it.

Still, would highly recommend it, the free version is brilliant.
Kushan is offline   Reply With Quote
Old 02-09-2014, 14:55   #15
pip08456
Sad Doig Fan!
 
pip08456's Avatar
 
Join Date: Aug 2007
Location: Barry South Wales
Age: 69
Services: With VM for BB 250Mb service.(Deal)
Posts: 11,838
pip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny star
pip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny star
Re: Interesting report on TheRegister today

Quote:
Originally Posted by Kushan View Post
I also use lastpass, absolutely love it. Made out like a bandit recently with their 12month + 6month subscription giveaway, before they nuked it.

Still, would highly recommend it, the free version is brilliant.
Kush, I highly agree with you, Lastpass is brilliant. Going on what was said further up. Ben is correct, the password you set up with customer services is totally different to your MyVirgin account, IRRC you set it up after going through the security checks that you may have been used to.

Although passwords first entered onto websites are done so in plain text they are normally stored on the site (nowadays) in 256Mb encription. Quas will most likely confirm.

I am still trying to figure out the reason for the Original post??????
pip08456 is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 08:33.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum