1and1 ask for passwords over the phone
blog.tim-rogers.co.uk
blog.tim-rogers.co.uk
I use 1&1, and I ran into the same situation a couple months ago: I was terminating one of my contracts, and they asked for my password over the phone to verify. To be clear: I was not closing my account, I was only terminating a single contract.
The way I "resolved" the matter was quite simple: as I am not stubborn, I just gave them my password. The person sitting on the other end of the phone call already certainly has godlike access to my account anyway, I am not stupid enough to use the same password for multiple accounts, and barring insanely epic hacks I know they are a real representative as I called them at their phone number; so, there is really very little to lose handing over my password to the customer support person.
In the end, rather than getting morally outraged and posting an article asking a question to an online community in the hope of unblocking your ability to conduct what is fairly simple business, you should just change your password when you are done with the call and move on with your life. It will save yourself a bunch of time and frustration.
Then, afterwards, if you don't like the way 1&1 operates (maybe you believe that this is indicative of a more underlying set of security mistakes, or maybe you simply don't agree with the practice and don't want to support it), you might then consider moving your accounts to a different provider: there are tons of people you can use to host servers, domains, or whatever else you may be using 1&1 for. However, it shouldn't block your ability to make things happen right now.
Even if not for me alone, I'd like to see this resolve as it's just bad form. A company culture that allows this cannot be good for the security of all domains held with 1and1.
I may well move away anyway, as you say, as I'm just so disappointed, but I'd like to see change anyway.
This post seeks to address information failure, if you will.
It's likely I and many other readers of this article will now never use 1and1 if it's possible to avoid them. A sort of passive boycott if you will.
1) change current password to some stupid password
2) give password
3) reset password back to my normal password
4) move on with life
So, he should give them his password, but he should then change it.
I have no problem with someone standing up for what they believe in, taking a stand, and "rallying the HN troops" for what might be a relatively minor issue for most. I'm sure we all have made fusses about more trivial things :)
Now, that said, I actually do believe people "rallying troops" is often knee-jerk and incorrect vigilante justice masquerading as valiant. It isn't always the case, and there may be places where such behavior is legitimate (although I think figuring that out is an interesting and horribly long off-topic discussion). It certainly, though, isn't always positive.
As an example, there person claiming on HN a couple days ago that Apple must be storing passwords in plain text because of a 32-character password length restriction[1]; I doubt that was actually the case, and much more argument and research should have been made before trying to incite such panic.
(edit: Hell, I didn't even notice that you did it yourself here until I saw the response from Fargren, but you just did it, too: there is no reason to believe that 1&1 "stores these user passwords in plaintext". It is much more reasonable to believe that they have a box on their end for "customer password" that verifies it using the same mechanisms the website does. It is not at all reasonable to "rally the troops" over assumptions.)
Again, however: that is not what this article was about; this article was not attempting to "rally troops", this article was asking for help making progress with an account they have at a vendor because the OP "make a point of never, ever, ever giving [his] password out to anyone" (emphasis his).
After all, you can still "rally the troops" after you get your job done: you can change your password afterwards, you can even change your password beforehand as borlak indicates (although that implies your password was important, which is already a mistake), you know this person is a real representative to within any reasonable margin of error; the morale stance here was just stubborn. :(
I just wanted to make sure people were aware of this kind of practice at 1and1, and hopefully (but probably not) drive some change in the practice.
Upvotes on Hacker News would be greatly appreciated to help me beat Goliath!
I took that to be a rallying cry :)I don't consider myself stupid and I used to use the same password across multiple accounts. I changed this practice a while ago but I know that for the vast majority of people they do reuse passwords frequently.
Suggesting people are stupid for not following best practice password management is not helpful to the discussion.
But incompetent security by people who should know better is not limited to a few internet hosting providers. A year or two ago, Chase Bank called my wife up (i.e. they called our home) and asked my wife for her credit card number. My wife refused to give it and they suspended her bank account because of it. She had to call them and spend an additional hour on the phone getting that straightened up and shortly after this they abruptly cancelled the account with no explanation.
Any time this sort of thing happens do yourself a favor and do whatever you have to in order to close your account and move somewhere else.
* Tier 1 customer service people do not have plaintext access to customer passwords, and
* Tier 1 customer service people do not have the ability to manipulate customer accounts without their passwords (and thus consent).
On the scale of security/customer-service interactions at service providers, this sounds like MONUMENTAL EPIC WIN. What exactly am I missing here?
And,
How on earth could you possibly input a password into some random text field in an application that you would not provide to the CEO of the company hosting that text field?
As for your second point, all that is based on trust in the company that they're not storing in plain text and opening it to the CEO...which I hope is the case for most companies. I was more trying to give a sense that I'm really not happy giving my password to any person. When it's a web form, you just have to have trust or the whole idea of passwords is broken.
Your first point is just innuendo, right?
Now, having seen some of the alternative systems suggested, I think I agree.
I instinctively do not want to give my password to anyone. And that's a great habit to get into, and we want regular people to get into that habit. That would make phishing less useful.
In this case it seems they're trying really hard to protect your domain from harm. But yes, I've been mostly persuaded.
As we've seen with recent breaches, the last 4 digits of your CC # aren't incredibly hard to find out. "Secret" questions and answers are generally quite poor, in that very few of them don't suffer from laughably small keyspaces or rely on semi-public information. Passwords almost seem like the least bad option.
I get that giving a password to a human isn't a very comfortable feeling, but if you don't trust the CSR to not misuse the password, do you also not trust the developers to not have put in something to grab your password one of the various times you enter it into a web application that they control?
Given the relative simplicity, I wonder why nobody (at least that I know of) has implemented something like this?
As for your second point, that is true - we just have to trust that that isn't happening, but that trust is implicit in day-to-day use of the internet.
So if they call you, never give anything related to security. Always call them back on a publicly verifiable phone number before giving security or very private info.
1. Login to your account
2. Click on "Request Support"
3. In the dropdown "Grant access to support for:" choose "30 minutes"
4. Submit the form
5. The site displays a phrase such as "banana black puzzle lightbulb"
as well as a phone number to call or a support form to submit.
The words are chosen from a list of 256 common, unambiguous words
making the odds of guessing 1 in 4 billion.
6. The CSR, upon using this phrase, gets 30 minutes access to your
account through their support portal only. All CSR actions are
logged in your account which you can view.
Of course, this takes development time away from features. It's much easier to just ask for the password and login using the same interface users use.Or is the point that somebody could wiretap you? Get off your tin foil hat and think about keyloggers.
¹) Or do a challenge response. It does not matter. It's a shared secret.
I don't understand what your issue is with telling them the password? Just change it to something random and change it back after if it's not something you are comfortable sharing or saying out loud. It may personally offend you, but t's certainly not a bad practice.
Seriously. There are way better providers out there.
But the place where I hated them most was NS change propogation, it took 24 hours to get that done.
Also their admin panel is awfully slow.
If you guys don't already know it, here are some of the links to help
To transfer/cancel domains you must go through : http://cancel.1and1.com
Admin: http://admin.1and1.com
Now I can of course access their mailbox by going into a shell on the server but the quickest way to check everything and satisfy the customer is to setup their email account on my computer and check I can get it to work.
Since the passwords are securely hashed, the only way I can do this is by asking for the password from the customer.
This sounds like 1&1 just doesn't have a real customer support story and should probably just be avoided if possible. Or find somewhere that lets you provide 2 part security (ie, one for personal access and another for support access).
Author of the post said they should have some backend, and maybe they do, but I think the biggest problem was that they wanted him to authenticate himself as genuine with them by providing his password... they should have some other way to verify his identity without that.
(This is my personal opinion as a security professional and not the opinion of my employer)
To me, it seems like they just have a badly thought out verification process when they should be doing something else - for instance, they could just the last four digits of your payment card or some other piece of relatively secret information. You have indeed crystallised what my issue is in this situation there!
UKReg.com
Domainmonster.com
123-reg.co.uk
All have solid reputations with 123-reg being the elephant in the industry but UKReg and Domainmonster having superb responsiveness and customer support.