Not only does Plusnet store passwords in plain text, call centre employees can see that plaintext when you call in http://www.theregister.co.uk/2015/11/25/plusnet_still_delivering_passwords_plaintext/ …
-
-
Replying to @qntm
That's how Plusnet verifies your identity over the phone. They ask for a few characters from your password, verbally.
1 reply 0 retweets 3 likes -
Replying to @qntm
Usually one or two of the first five or six characters, so the customer doesn't have to count too far, apparently
1 reply 0 retweets 3 likes -
Replying to @qntm
So a Plusnet call centre employee could just log in as any customer, see their email, etc.
1 reply 0 retweets 2 likes -
Replying to @qntm
. Passwords are encrypted in our database. We do not show customers their passwords in an email in plain te... https://plusnet.response.lithium.com/portal/conversation/18417778 …
1 reply 1 retweet 0 likes
Passwords are visible in plain text to call centre employees. This should be impossible. They should be hashed, not encrypted
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.