Virgin Media stores user passwords in plaintext?
twitter.com
twitter.com
However, Virgin don't seem to have clarified if and how the online log in password is hashed.
[0] -https://virginmedia.response.lithium.com/portal/conversation...
"Only Virgin Media staff are able to view your password in an camera free enviroment. How would you take care of peoples sensitive banking details? MCr"
https://virginmedia.response.lithium.com/portal/conversation...
This isn't anything to do with account logins etc. No different than companies asking you to verify your DOB and address to prove who you are.
If I were to call up Virgin and say, "Hey, this is MattBearman, I want to add a phone to my account and an international calling plan," they need a way to verify that I am MattBearman. Instead of asking for personal information, they ask for an "account password" which is not your online password and is only used for the purpose of identifying the caller.
It has to be plaintext or encrypted; they're not going to give you a hashing algorithm to work out over the phone.
http://plaintextoffenders.com/post/4983474119/virginmobile-c...
I'm with virgin mobile australia and I get the same mail when I click on "Forgotten Password" when I try to log into my online account to pay my bill.
- They're doing things correctly
- They ask for a code over the phone to verify your account
- Their Twitter guy refers to this as a "password"
- Nobody reads anything on the internet, therefore everybody is concerned and fighty.
There's no indication of how passwords are actually stored. This is all about the passphrase you tell the guy on the phone so that he can verify your account. It seems reasonable that that guy would need to be able to see that word on a screen so that he can compare it to what you say.Still, it's good that people are still really angry about this, 23 hours after their support guy explained what's going on.
Here, the operator forwards you to a machine and you input your phone password, so the operator does not know your whole credentials.
Let me be clear: Phone passwords are superior to phone pins, phone secret question/answers are superior to both, and the agent needs to be able to verify the secret question/answer set, and also the password. You CAN design it so the agent cannot see the whole password, but that means the agent cannot use common sense to account for differences in spelling, or interpretation e.g. "to" as 2, to, two, and too (plus "the third digit of your password" is hard for humans, we aren't designed that way).
People saying things like: "an agent cannot be trusted!" Are missing the point, that the entire system is built on agent trust. When you call you're purposely giving this agent access to your account, making the password useless, there's no proof they logged off when you hang up, there's also no proof that they aren't writing down your responses and will then relay it to another agent later.
A lot of people who whine about plain text in particular don't really seem to understand what it is that hashing even does. They seem to think things like: "if you get hacked, someone cannot steal passwords" (nope) or "then someone cannot sniff your password over free wifi" (nope). All hashing does is add time between the hack, and when the hacker can start using the stolen credentials, that's it. It is there to give the company time to detect the leak and to notify/reset, if the company fails to detect then it has done absolutely nothing of worth.
To be honest I find "HTTP offenders" (e.g. HTTP web-sites that redirect to HTTPS login forms, essentially breaking HTTPS's MitM protections) far worse than "plain text offenders." But none of this has anything to do with calling out security issues at this point. A bunch of people who don't seem to understand the technicals here feel like they're doing "good" by calling out companies for things that don't even make sense.
Whoever runs their twitter also later claims that this account password is different than their online password, which seems to support that it's more of a PIN than global password. I'm not a Virgin employee or customer though, so I'm not sure if this is the case or not.
- Type in my account number
- Wait for an agent
- Get an agent. Give my name and account number
- Explain my problem
- Get transferred to another agent
- Wait
- Get an agent, give my account number
- Give the third letter of my password (which got me confused, as I thought they were asking for my account password)
- Explain my problem
- Get transferred to another agent
- Wait
- Get an agent, give my account number
In the end, I talked to three persons, in the same company, and gave 4 times my account number, and one time my "password".Can confirm, does not save time at all!
Note: this is for Virgin Media UK. Did not experience that with Virgin Media in Canada.
Virgin's hardly the only one doing this. ADT reps ask for a password when verifying an alarm. At least its better than just asking for your name and address.
This is known since at least 2013: http://www.kitguru.net/gaming/security-software/jon-martinda...
Edit: Others are saying this is for the "phone verification password", but my password is to log into the online account to pay my phone bill.
And that one's from 2011!!
One part of me wishes that the governments of the world would just outlaw this kind of idiocy. On the other hand, I'm not sure if I'd like that much regulation. I certainly wouldn't want to be a developer in a world where I can get sued for using a non-NIST-approved algorithm or something.
Fortunately, "PCI-DSS" seems to be the magic word that can developers can use to beat sense into people's heads most of the time.
I'm glad I never reuse a password.
What should really be happening here is the discussion being escalated to their systems / security team and an official open letter published.