-------------------
Hello All,
Rest assured, passwords are encrypted. We do have one-way password hashes for certain combination to make it possible for CS to validate the authenticity of the customer. The support representative is not shown the full password.
To make it even more secure, we too have plans to implement an option to specify a 'Support Security Code' that can be provided for communication with CS instead.
Thanks, Mohan
Namecheap.com
http://www.webhostingtalk.com/archive/index.php/t-886490.htm...
It is like I heard from a friend who knows someone who's father works there kind of thing without evidence.
+ the person who reported this wasn't some noob, so I trust him
oh and i found out by talking to their support people. I
didn't believe the dude when he told me, so i asked him
for some random characters (i.e starts with, ends with
etc) and he had the right anwsersThree recommendations:
* head /dev/random | md5 # very annoying to type, though
* ruby -e 'puts rand(1<<128).to_s(32)' # less annoying to type
* Keychain Access password helper at "memorable, 31 long"
Note that FedEx has the same bad behavior.
The real risk here is to Namecheap, who is utterly exposed in the event of a database leak. If they're keeping online plaintext passwords, they'll have nothing to say to mitigate the catastrophic damage of giving up many of their customer's most sensitive credentials.
Alternatively, strings /dev/random|head gives some stuff that you can concatenate into a password.
openssl -rand base64 12
On your favorite Unix.
May I have your username along with the first and third character of your password?
It would be funny if they had hashes of every combination of passwords. Hopefully, it's just one.
This is pretty goofy. Among other things, those customer services will themselves be trivial to break, and are probably password-equivalent (use them with support to reset your real password).
This looks like a case of a company going out of its way to be marginally less secure than a typical non-secure framework application.
Now with this whole password security potential problem, just curious if there are comparable solutions out there for API access...