Thames Water don't get password security
shkspr.mobi
shkspr.mobi
If any company asks for the 4th character of your password, that means they are storing your password in a reversible fashion, and they should be dumped.
The online account should never be logged in by anyone other than the owner. The person on the phone, if their job requires it, should have read/write access to your account, but that should be audited as "Joe Bloggs" accedsing the account
The only reason we need unique passwords is because the system can't hold up its end of the bargain.
Edit: And in hindsight, I was wrong in calling it a bad password from the user - the only reason it's necessarily bad is because it has been compromised. If I use the same sufficiently complex brute-force proof password everywhere, we can safely say I've held up my bargain, but a single data breach completely removes that otherwise impenetrable defense.
Seems like it may be an unfortunate 'trend' for banking services in this country.
You can't hide individual letters of alphabet with a hash. Not even with a salt and an expensive hash. It's a hopeless case where a brute-force attack takes only 26 times (or 676 for a pair of letters) longer than a comparison you do during normal operation.
BTW: it's also not possible to use hashes to hide/anonymize phone numbers or IP addresses. The attacker can generate hashes of all possible values and see which one is it.
I’m so glad I don’t live in the UK anymore.
Well, me too. But I'm curious where you live now, and if you think that things are truly better there?
Anyone else in a similar situation should be able to resolve the matter by complaining to the Consumer Council for Water. In the staggeringly unlikely event that this did not resolve the situation then taking Thames Water to small claims court would be the next step.
There needs to be someone saying "you restricted your passwords to 8 alphabetic characters, your C-grade in charge of security can no longer hold a position that involves security, and you company must pay 50% of profits (subject to a minimum of 5% of revenue) as a fine.
With a very clear, basic, definition of minimum security levels for companies (above a certain size) to comply with.
We can't leave security to the market as the information isn't public and the market on the whole can't comprehend it.
"You're new account number is <big string of digits>, you must go to the website and enter it there to re-register."
Uh.. ok? (Leaving aside that this reads like phishing, I go to the website.)
`input_mode="numeric"` prevents me pasting the <big string of digits>, so I get rid of that, paste it, feel briefly sorry for customers that won't know to do that, and then it errors anyway.
They shouldn't even be able to know what your password is. They shouldn't have a copy of it anywhere. Only a hash function (or several) of it.
It should be impossible for any of their staff to ever obtain your password, or tell it back to you, or verify that you're reading it to them correctly -- BECAUSE they don't have a copy of your password ANYWHERE.
> So, we came up with a compromise. They would reset my password, log in to my account, fiddle around with it, and then call me with the new password. And so they did.
I'm not sure that the staff did in fact have access to the password. It sounds as if they needed to log in as the customer to make necessary changes, so the password request was in the context of a login attempt.
Of course, this just raises further questions about how they manage their systems, if they cannot administratively perform any action required without acting as the customer.
In many applications it is important for support staff to be able to access your account in certain ways, but not other ways.
UK Residential water customers fall into basically two categories. Older residences that haven't converted are billed based on "rates" - a guess of what a residence like that uses on average. Newer ones, or if you opt in to have a meter fitted are billed for metered water usage plus (unless exceptionally they have water but no sewage provision) a proportional amount for sewage. There's a discount if you've at least set things up so that rain water doesn't get dumped into the sewer.
But none of this is controllable, so for anyone with financial stability the obvious thing to do is set up Direct Debit (in the UK the law lets you give your bank account details to approved businesses like the water utilities and then the bank just gives them whatever they ask for, the law includes a safeguard so you can retrospectively unwind this with no questions asked) and then forget about it.
If you're too poor for Direct Debit to be wise (residential water can't be shut off for non-payment since courts consider it essential, so if you've got £10 left in the account until the end of the month you don't want the water company taking that money which could otherwise buy food) you still can't do anything about that by having an account.
So I've never had such an account and can't imagine how I'd use it. When I have had a dispute with the water company in the past an account wouldn't have helped, I needed to argue with actual humans about why they were wrong.
Am I so worried about the security of my water bill that it needs to exist behind a password? I’m perfectly happy if anyone who wants to put my address into the website can see exactly how much I currently owe. They can even pay it for me if they really want to.
But if you need to put in your own meter readings I get that that’s different. I’m really complaining more about my own local utilities and other companies that have totally pointless passwords that make paying bills extra difficult.
Why are you getting a new account number every month?
Why can't they add it to your online account automatically?
Why can't they access settings in your account with you login in as you?