If I was on Hover (which I considered), I'd transfer my domains immediately. Moving to a plaintext password system to get fewer support requests is like removing the door from your house so you don't have to keep fumbling for the key.
If I was on Hover (which I considered), I'd transfer my domains immediately. Moving to a plaintext password system to get fewer support requests is like removing the door from your house so you don't have to keep fumbling for the key.
Hi -name-,
Can't remember your password? Don't worry about it — it happens. We can help.
Username: -username-
Password: -password in plain text-
Please keep your password safe to prevent unauthorized access.
It blows my mind that even 37signals falls for this trap. There should be a website showing a blacklist of services that store passwords plaintext.And another one to add to the list: my brother's small business uses British Telecom for email hosting. Their control panel stores the password in plaintext.
What's the use of encrypting your passwords when you're broadcasting them to every mail server between your and your customer?
So I wonder if they should instead allow "authentication-by-email". Basically, make it work just like current reset emails (with an embedded randomized link that allows access), but prevent the link from expiring.
Obviously that suggestion has a lot of holes in it, too, but it's something to consider, especially since it's not a new idea.
Either way, it's a real amateur move to do away with hashing.
Email auth really should be done as Joakal says - your public key stored on their server when you sign up, email auth is encrypted. Trouble is, it's "too hard" for "normal people". If gmail/outlook etc supported it, though, it could catch on.
It's worse in some ways (control, usability, security) and better in others (simpler technologically, everyone has it).
What registrar would anyone say is the most security focused and/or government resistant?
Maybe it should be a 2011 AskHN?
Can't recommend Gandi enough, they do exactly what they say on the tin - "no bullshit".
I wouldn't say they're security focused, but they allow you to be totally anonymous in your registration, and have a policy of hosting anything that isn't illegal.
But I like how they send you an email on every failed auth attempt.
There should really be some minimal set of conditions for domain registrars, with one of them specifying a reasonable security model for password retrieval.