T-Mobile Stores Part of Customers' Passwords In Plaintext, Says It Has 'Amazingly Good' Security https://motherboard.vice.com/en_us/article/7xdeby/t-mobile-stores-part-of-customers-passwords-in-plaintext-says-it-has-amazingly-good-security?utm_campaign=sharebutton … via @motherboard
-
-
It is not secure for a verifier to store passwords in encrypted form. The moment you have both a ciphertext and the corresponding key stored, a breach of both will reveal the cleartext of the passwords.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Helmut wo ist Käthe hin
-
Helmut wir brauchen Antworten geht es ihr gut
-
Käthe verliert ihren Job nicht. Die Antwort war in der Hitze eines Twitter-Threads offensichtlich nicht klug. Die Mischung aus Häme, Hetze und „Feuert Sie“, die dafür aus manchen Tweets kamen, sind hingegen erschreckend.
-
I don't think she should be fired, however a PR job clearly isn't her cup of tea. Imagine someone received a clearly rancid cut of meat at a restaurant, and the manager dismissed any concerns with empty platitudes like "we take the freshness of our ingredients very seriously."
-
...and then followed it with a snarky "Who are you to tell us this meat is rotten? Are you a food safety expert or something?"
End of conversation
New conversation -
-
-
Two-way encryption is in no way an industry standard for storing passwords. it's an embarrassment.
-
FYI, there's no such thing as a "one-way encryption." Encryption implies an ability to decrypt. Hashing is one-way. Saying "two-way encryption" just sounds redundant, and comes off like you have no clue what you're talking about.
-
thanks mr. mansplainer. i knew that already, your wise guy correction behaviour was not needed, i just didn't fit a complete detailed pamphlet about how cryptographic hash functions work into my tweet. go be an obnoxious pedant somewhere else, bye
-
So then why would you say two-way hashing? Sounds pretty ignorant, but looking at your Twitter profile, you seem like a typical Eurodiot... so nothing unusual there. "Does stuff with IT Security" is actually very alarming. Shouldn't people that do know what they're saying?
-
*facepalms*
-
Pretty much me to you. Listen, little "girl." Don't play with things that you shouldn't be playing with. Leave security to those that know what they're doing and what they're talking about. I just hope that no one trusts you to run actual security on a business level...
-
Tweet unavailable
-
dat sweet, sweet plonk sound, gotta love itpic.twitter.com/E6oMAiSwK4
End of conversation
New conversation -
-
-
You store the passwords encrypted, and the decryption key is available both on the server for http://mein.t-mobile.at (Nice error page btw: http://keinzugriff.t-mobile.at/403.html?error_id=amazingly_good …) and on the customer care backend servers (for verification)?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Two valid responses here 1. We don't care about customers' security, GDIAF 2. We apologize for putting our customers at risk and will be switching to *hashed* password as soon as possible There is no option 3. There is no such thing as a "safely encrypted password"
- 1 more reply
New conversation -
-
-
It doesn't matter how secure you think your encryption on your database is. Storing any part of a password in plaintext is illegal in many industries- and there's a reason. You guys might want to start assuming you are unemployed. Your bad Opsec team as well.pic.twitter.com/Vg4CVgAvlO
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
"Industry standard" for passwords is one way hashes
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
sounds to me like you are storing cleartext passwords in an encrypted database? You understand that a SQL injection issue could still lead to a massive breach of cleartext creds right?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.