Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
Password Not Encrypted - Consumerreports.org
Message
De
28/06/2007 09:29:53
Mike Cole
Yellow Lab Technologies
Stanley, Iowa, États-Unis
 
 
À
Tous
Information générale
Forum:
Internet
Catégorie:
Autre
Titre:
Password Not Encrypted - Consumerreports.org
Divers
Thread ID:
01236264
Message ID:
01236264
Vues:
77
No, this isn't another thread about UT password security...

A month ago my wife and I subscribed to Consumer Reports and they gave us an online account. I logged in immediately and looked up info about a TV I was looking to buy. I haven't used it since.

This morning I decided to log in because I need a new wireless router and I wanted to see what their reviews were like. I couldn't get in, and I emailed me wife to ask her out login name because I thought I had that wrong (I knew what our password was). She replied that she tried to get in the other day, but couldn't. She tried the password reset feature but her email address didn't work, and she couldn't get it reset. She said she was going to call this morning to get it figured out.

She called, and talked to dingbat-queen on the phone. The lady told her that we never had an account online, and my wife told her that we logged in like 3 weeks ago. The lady was persistant that we never had an account. Then the lady asked "Is your password this: " and gave us a password. My wife said no, and the lady said, well that is the password that is set for this username.

So my wife sent me the new password, and since it was for the same username that we had I thought that somehow it just got reset to something odd. I logged in, and just out of curiousity looked at the account information. No, it isn't us... it's some chick in LA with my wife's name. I can see her address, her email address, and the last 4 of her CC number. I also suspect that this password would work with her online email account, but I haven't and won't try.

So if you have an account with ConsumerReports.org, you might want to make sure your password isn't the same as anything else, because they apparently give it freely over the phone.

The security officials at my workplace would tear that dingbat apart if they talked to her.
Very fitting: http://xkcd.com/386/
Suivant
Répondre
Fil
Voir

Click here to load this message in the networking platform