Welcome to GatorChat! You are being connected to a representative in our Technical Support department right now.
(01:33:17 PM) Joe: hi there.
(01:33:26 PM) Nathan: Welcome to Hostgator LiveChat. My name is Nathan. How may I assist you today?
[...]
(01:38:30 PM) Joe: never got password
(01:39:20 PM) Nathan: Its the same as your billing password.
(01:39:46 PM) Joe: YEAH
(01:39:48 PM) Joe: I JUST GOT IT. WHICH MEANS YOU GUYS KEEP PASSWORDS IN PLAIN TEXT
(01:41:01 PM) Nathan: Correct.
(01:41:26 PM) Joe: it would be good to have more security in place :)
(01:42:44 PM) Nathan: What is not secure about what we do?
(01:42:58 PM) Joe: the password. kept in plain text
(01:43:46 PM) Nathan: Its a very secure password, dont give it to people and you will be secured.
(01:44:16 PM) Joe: no. you dont understand. i'm saying: keeping password not encrypted or hashed on registryrocket.com part is not secure
(01:45:21 PM) Nathan: No one should know your billing password Joe. We see no reason to create a new password for that.
(01:45:39 PM) Nathan: I apologize.
(01:46:08 PM) Joe: no problem, but you still dont get it. if hackers hack into registryrocket, they have a database of domains and passwords for each domain. in plain text!
(01:46:31 PM) Nathan: Okay, you can change the password if you want.
(01:46:58 PM) Joe: but what if I change it today, and hackers hack into registryrocket 2 hours later?
(01:47:20 PM) Nathan: Then we will change the password. I dont understand how hackers would randomly guess your password Joe.
(01:47:59 PM) Joe: they dont need to randomly guess my password. my password is stored in registryrocket database in PLAIN TEXT
(01:48:45 PM) Nathan: Please show me where you can see it.
(01:49:10 PM) Joe: I cant!! I did not hack into registryrocket
(01:49:36 PM) Nathan: Okay, no hackers are getting into our database Joe. I do not understand how they would get your password.
(01:49:44 PM) Joe: but if someone WILL hack into registryrocket AND copy the entire database of users/passwords, then those passwords wont be encrypted or hashed, they will be in plain text
(01:52:20 PM) Nathan: Joe, no our passwords are encrypted with MD5.
(01:52:29 PM) Joe: impossible!!
(01:52:34 PM) Nathan: No one is going to hack into registryrocket.
(01:52:35 PM) Nathan: Okay.
(01:53:01 PM) Joe: ?? how can you encrypt password with MD5 and within 10 seconds from clicking "remind password", I got my password in my mailbox??
(01:53:54 PM) Nathan: Joe, our passwords are secured in a database. Please do not worry about us getting hacked. We have it under control.
(01:54:16 PM) Joe: you misleading me.
(01:54:40 PM) Joe: passwords CANNOT be properly encrypted in the database AND the same time you sending me password 5 seconds after I clicked "remind password"
(01:56:07 PM) Joe: even for very powerful computer it would take much more than 5 seconds to "decrypt" (or should rather say: crack) MD5-encrypted password
(02:00:35 PM) Joe: any news, Nathan?
(02:01:28 PM) Nathan: Our passwords are not MD5 encrypted, but they are encrypted and its done by Enom.
(02:03:06 PM) Joe: (01:52:20 PM) Nathan: Joe, no our passwords are encrypted with MD5.
(02:03:15 PM) Joe: whats "Enom" ?
(02:03:20 PM) Nathan: I apologize I made a mistake. Enom is who we sell our domains through.
(02:03:45 PM) Joe: ok, what do they use to encrypt passwords??
(02:03:55 PM) Nathan: I would not know.
(02:04:11 PM) Joe: I tell you: NOTHING
(02:04:54 PM) Joe: thats why most websites you CANNOT retrieve your old password, you can only reset it.
(02:07:22 PM) Nathan: What can I help you with Joe? Do you need the password to login?
(02:07:48 PM) Joe: I was just wondering how secure my vulnerable data is.
(02:09:22 PM) Nathan: We have a secure database, we have not been hacked in the past and I don't think we will be hacked anytime soon.
(02:09:41 PM) Joe: ok thanks.
Current Rating: 12345