Results 1 to 7 of 7
Like Tree1Likes
  • 1 Post By essellar

Thread: Signup form doesn't mask passwords

  1. #1
    SierraAR's Avatar
    SierraAR is offline The Razgriz
    Join Date
    Aug 2010
    Location
    Washington, U.S.A.
    Posts
    806

    Signup form doesn't mask passwords

    http://sierrabrown.me/ss/phggq97.jpg

    The signup form on the front page of x10vps.com doesn't mask the password fields with asterisks (***). This is a bit of a security issue for public areas or people with nosey 'friends'.
    ***I am taking a break from support to focus on getting into college. Wish me luck!
    Sierra Brown | x10Hosting Volunteer Support
    █ sierra[@]x10hosting.com
    x10Hosting - Giving Away Hosting Since 2004
    Premium Hosting | VPS Services

  2. #2
    GtoXic is offline x10 Support
    Join Date
    Apr 2010
    Posts
    637

    Re: Signup form doesn't mask passwords

    Yeah, I can confirm this, tested in FF, Chrome and IE.
    GtoXic | x10Hosting Technical Support
    █ john.h[@]x10hosting.com
    x10Hosting - Giving Away Hosting Since 2004
    Premium Hosting | VPS Services

  3. #3
    bdistler's Avatar
    bdistler is online now x10 Lieutenant
    Join Date
    May 2010
    Location
    Catalina AZ USA
    Posts
    416

    Re: Signup form doesn't mask passwords

    just received my password by Email as "plaintext" - not nice

    I confirm the signup form shows the password as "plaintext" - not nice

    I assume from the above my password is stored unencrypted (same as "plaintext") by x10hosting

  4. #4
    leafypiggy's Avatar
    leafypiggy is offline Community Advocate
    Join Date
    Aug 2007
    Location
    Massachusetts
    Posts
    2,247

    Re: Signup form doesn't mask passwords

    Quote Originally Posted by bdistler View Post
    just received my password by Email as "plaintext" - not nice

    I confirm the signup form shows the password as "plaintext" - not nice

    I assume from the above my password is stored unencrypted (same as "plaintext") by x10hosting
    Without looking at the code, I couldn't say for sure, but I'm willing to bet your password is hashed in our database. Just because you receive an email with your password doesn't mean the password's being stored in cleartext (Correct wording, it's not plaintext). It's as simple as setting a separate variable with the stored password for email, or simple sending the email before hashing. As for the confirmation page - it's probably in the get params (or it's a cookie)
    Neil Hanlon | x10Hosting Support Representative
    Neil[at]x10hosting.com
    █ I'm always happy to help. Just ask a question in Free Hosting
    Terms of Service IRC

  5. #5
    essellar's Avatar
    essellar is offline Community Advocate
    Join Date
    Feb 2010
    Location
    Toronto, Ontario, CA
    Posts
    1,683

    Re: Signup form doesn't mask passwords

    Password masking should only ever be an option (or at the very least, there should be an option to render clear text). Y'all folks ought to keep up on security best practices—the object of the game is to encourage passwords with high entropy (longer is better, regardless of the complexity of the character pattern) and that results in greater opportunities for typos. Password masking tends to encourage simpler/shorter passwords.

    Emailing clear text passwords is generally a bad idea no matter how the password is actually stored in the login system (and one would hope that it's at least stored as a salted hash with a high work factor; preferable is both salt and pepper)—email systems are rarely as secure as one would like, and an email program (or a webmail page) is one of those things that's likely to be left open for an extended period of time.
    Sharky likes this.
    “Beware of bugs in the above code; I have only proved it correct, not tried it.” --Donald Knuth
    "It was as if its architects were given a perfectly good hammer and gleefully replied, 'neat! With this hammer, we can build a tool that can pound in nails.'" -- Alex Papadimoulis (on TheDailyWTF.com)

  6. #6
    Bryon is offline Administrator
    Join Date
    Apr 2005
    Posts
    7,706

    Re: Signup form doesn't mask passwords

    Quote Originally Posted by bdistler View Post
    I assume from the above my password is stored unencrypted (same as "plaintext") by x10hosting
    You know what they say about assumptions..
    Last edited by Bryon; 07-15-2012 at 05:59 PM.

  7. #7
    Corey's Avatar
    Corey is offline VPS Migration Professional
    Join Date
    Dec 2004
    Location
    Northfield, NH
    Posts
    17,347

    Re: Signup form doesn't mask passwords

    Just to clarify on somethings...

    I've never agreed with the masking password field thing on registration, it doesn't change the way it is stored\submitted on the server... only causes inconvenience for the user. Apparently it's to prevent shoulder peeping? As it is a simple change I'll go ahead and enable it.

    With that said, I understand the email issue... personally I change my passwords anytime I get it via email whether it's reset\registration, etc. But I understand not everyone does what I do, so I'll fix that so passwords are no longer emailed and if someone 'forgets' the email clearly tells them to login and change it immediately. If I have time I'll force a password change upon login from a reset.

    Passwords are encrypted in all of our systems, it was very difficult to do encryption with the VPN setup due to radius but it is done. Overall I think the way we handle things in general between all the systems\sites we have is very secure compared to the industry norm.
    Corey Arbogast | CEO
    █ 888-X10-9668 - corey[@]x10hosting.com
    x10Hosting - Giving Away Hosting Since 2004
    Premium Hosting | VPS Services

Similar Threads

  1. Replies: 2
    Last Post: 03-24-2010, 07:03 PM
  2. Mask Domain
    By drizzt09 in forum Free Hosting
    Replies: 1
    Last Post: 08-19-2008, 12:07 AM
  3. Mask Fowarding IP
    By jchiu in forum Free Hosting
    Replies: 1
    Last Post: 07-28-2008, 02:58 PM
  4. signup form to use SSL
    By jwade in forum Feedback and Suggestions
    Replies: 1
    Last Post: 01-27-2008, 07:32 AM
  5. Howto mask ?
    By Revolution in forum Free Hosting
    Replies: 0
    Last Post: 05-22-2005, 01:56 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
dedicated servers