• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / Security and Privacy / Avoid websites that store your password in plaintext

Avoid websites that store your password in plaintext

2012-07-03 by Jason

If you forget your password to a website and your ‘forgot password’ request is answered with your password being emailed to you, there’s a problem there. Your password should at least be hashed with one-way encryption and stored in the database securely. Even though it’s convenient, it’s very bad security. As was exhibited by several database breaches recently, even hashed passwords are only a matter of time to solve with rainbow tables of known password-hash matches. It’s bad practice for users to use the same password across multiple web services but it is equally a responsibility of web service providers to secure the information they are entrusted with.

If you are looking for a little name-and-shame, you can visit Plain Text Offenders. The site collects screenshots of web services that send out your credentials in the clear. If it’s done at registration, it might not mean the database holds unhashed passwords but you better hope your email never gets broken into if it stores the keys to the kingdom. In addition, sending out your email across the wire in the clear cannot provide much assurance that it wasn’t picked up somewhere along the way. If the site sends your password to you on a password reset request instead of a reset link, then you should definitely have concerns.

Concerned enough? You can search PlainTextOffenders.com before you sign up for a new service to see if they have been listed as using bad practices with passwords.

A Google Chrome extension called Password Fail will automatically tell you if the site you are visiting has been registered as storing passwords in plain text. However, I’m not sure if the extension and associated site list is kept up-to-date.

Do you use any other resources to keep your accounts secure and avoid companies that implement bad practices?

Filed Under: Security and Privacy

Trending

  • Windows SteadyState – Locking down public terminals
    In Security and Privacy, Software, System Administration
  • My Brush with Blog Scraping
    In Media, Talking Points, Tech Solutions
  • FreeMeter: a low-impact system monitor
    In Software, Tech Solutions

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • How to ‘Unblock’ multiple files at a time with PowerShell How to 'Unblock' multiple files at a time with PowerShell
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • Configure Outlook to recurring appointments for the last weekday of the month Configure Outlook to recurring appointments for the last weekday of the month
  • Read the Event Logs on Windows Server Core Read the Event Logs on Windows Server Core
  • SOLVED: “This modification is not allowed because the selection is locked.” SOLVED: "This modification is not allowed because the selection is locked."
  • 3d rendering circuit cloud for cloud computing technology Build and Deploy a Modern Web 3.0 Blockchain App in 2022
  • Telecom Application Development: When to Outsource Telecom Application Development: When to Outsource
  • Printer printing document wirelessly from mobile phone or smartphone wifi connection vector flat cartoon illustration, file air print on fax or ink jet via cellphone bluetooth modern design Why Your Business Needs Online Fax Services In 2022
  • 6 Best Ways to Protect Your Business Account 6 Best Ways to Protect Your Business Account
  • How to download videos from Instagram How to download videos from Instagram
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • Build and Deploy a Modern Web 3.0 Blockchain App in 2022
  • Telecom Application Development: When to Outsource
  • Why Your Business Needs Online Fax Services In 2022

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2022 · Magazine Pro Theme on Genesis Framework · WordPress · Log in