TMobile confirms they store passwords in plaintext, don't see why it's a problem
twitter.com
twitter.com
"What if this doesn't happen because our security is amazingly good? ^Käthe"
This is begging for it.
And doubling down as well, that’s a bold strategy.
I know, and it ain’t fucking pretty. Plaintext passwords (and stupid customer service) are just the tip of the iceberg.
Telcos are right up there with internet-connected industrial control systems when it comes to security and the huge fallouts of a breach.
What’s often lacking though is a clear path for reporting security issues to people such as this representative. They don’t have a process to flag something for the security team.
[1] https://twitter.com/fabricio_giglio/status/98236273592413798...
The problem with telecom companies is they have customers from a wide spectrum of technical capabilities. Their systems need to be able to support the baby boomer who calls support because they can’t remember their password, pin, or something...
I’m not defending these practices by any means, but these society-spanning institutions are facing challenges of balancing usability and security that many companies do not need to worry about.
If a company wants to implement a system like this, fine. But please tell me before I enter my password so I know not to reuse another password of mine.
At what point do we just have to leave these people behind?
So, you never worked for us in Austria though. But thank you very much for sharing your opinion.
-> Thanks for stating that you seemingly haven’t understood what we’re trying to tell you.
-> Oh, I do get it. I hope you enjoyed my responseI wonder how this feature came to be? What were those meetings like?
Every T-Mobile (including the US one) is owned by Deutsche Telekom, but most of its subsidiaries are named differently. For example, Macedonian is called "Makedonski Telekom" instead of "T-Mobile Macedonia".
This needs to end. Kinda like building a bank without locks. Insane.
I think most people would agree that in this day in age, leaving passwords in plain text is like not even making the effort.
If you didn’t lock the doors on a bank, that would be the same thing - not making an effort, even though many criminals can pick a lock. So yes, the analogy holds up.
While that was true before GPUs
>To a modern attack, salts quite simply don’t help.
Everybody should really move to key derivation functions (ideally scrypt)
Is N=14, r=8, p=1 good enough?
https://mobile.twitter.com/alex_duf/status/61472768376378163...
Re-reading myself, I should have been more polite and less smug I think, the community manager never asked for that.
Hoping this blows up. Time to short.
After a valid pin has been entered or X invalid tries by the customer service agent the customer needs to request another support pin.
Now this doesn’t doesn’t mean that the transmission of SMS is 100% secure but as they operate the network they could be in a much better place to validate that a request came from and was delivered to a phone and sim on their network (if the customer is on network and not roaming, but would be a bit of a shit customer support experience if you could only get support on network).
Just saying that the one time, limited lifespan support code system can be done securely so let’s not throw them under the bus just yet.
Edit: Using support pins delivered to the phone should only be treated as proof of being in possession of the sim and not proof of being the account holder.
I understand though that no one being able to know the password except the user is utmost security, but why not encrypting it ?