Go Back   HostGator Peer Support Forums > Public Forums > Suggestions

Notices

Reply
 
Thread Tools
  #1  
Old 05-13-2007, 02:52 AM
DarkSorrow's Avatar
DarkSorrow DarkSorrow is offline
Swamp Croc
 
Join Date: Nov 2005
Location: Reeds Springs, Missouri
Posts: 250
Angry Billing Changes

I would like to show you how unsecure your billing portal is. It is a pure security risk to email our password and login details on monthly invoices!! Please remove this feature or block it!

Sample from Billing Invoice

Paypal

If you pay using paypal DO NOT send a payment to our email address. To pay you will need to login at :

https://secure.hostgator.com/billing/
Username: **Removed**
password: **Removed**
__________________
sudo rm -rf /mnt/win32 ; sync ; dd if=/dev/random of=/mnt/win32/ooops bs=16384 ; sync
"Knowledge is Power, power corrupts, corruption is illegal. STOP LEARNING BEFORE YOU END UP IN JAIL!"
Reply With Quote
  #2  
Old 05-13-2007, 07:16 AM
Sam Sam is offline
Emperor Croc
 
Join Date: Jan 2007
Location: /bin/false
Posts: 3,057
Default Re: Billing Changes

Why is it a security risk? only YOU will get the email so nobody else will see it.
Reply With Quote
  #3  
Old 05-13-2007, 08:48 AM
gtgeorge's Avatar
gtgeorge gtgeorge is offline
Emperor Croc
 
Join Date: Mar 2005
Posts: 2,223
Default Re: Billing Changes

Quote:
Originally Posted by _Sam_ View Post
Why is it a security risk? only YOU will get the email so nobody else will see it.
Since when is email only something you will look at? The data is there for anyone to look at for any server it passes through.
__________________
best regards,
George
Reply With Quote
  #4  
Old 05-13-2007, 09:20 AM
Serra's Avatar
Serra Serra is offline
Veteran Croc
 
Join Date: Feb 2005
Location: Orange Park, FL
Posts: 5,073
Default Re: Billing Changes

Quote:
Originally Posted by gtgeorge View Post
Since when is email only something you will look at? The data is there for anyone to look at for any server it passes through.
That is basically correct. Emails are passed open from system to system. Even if you pickup your mail with SSL, it was sent to your server open.

In the past, sending plain text passwords was a very large problem because hackers would use sniffers to watch for traffic with passwords, credit card, ssns and that type of stuff.

Now days, sniffers are not nearly the problem they were because of the volume of traffic. Sniffers produce so much volume that its really impossible to use them effectively any more, unless the hacker is targeting a specific source/destination. The majority of hackers are now using keyloggers and trojans, not sniffers.

IMHO, sending passwords in email is not the problem it was years ago. I can't remember the last time I head of a system being exploited via a sniffer. I routinely send emails with passwords and don't think a thing about it, its not secure, but its safe enough for passwords. I don't think its safe enough for credit card numbers, because of their format, they are still very easy to sniff and profitable when found.

Also, I suspect that if the billing system was ever exploited, they would stop sending passwords, but as that doesn't seem to be happening, it does seem to bear out that it is safe enough.
__________________
Six stages of Dedi Ownership

Fashionable broken link
image included

Last edited by Serra; 05-13-2007 at 09:25 AM.
Reply With Quote
  #5  
Old 05-13-2007, 03:18 PM
GatorDaveC's Avatar
GatorDaveC GatorDaveC is offline
HostGator Staff
 
Join Date: Mar 2006
Location: Ontario, Canada
Posts: 937
Default Re: Billing Changes

Hello,
We have changed the billing system to only send the password when you receive your welcome e-mail. You should not see the password in new invoices now.
Reply With Quote
  #6  
Old 05-14-2007, 03:16 AM
DarkSorrow's Avatar
DarkSorrow DarkSorrow is offline
Swamp Croc
 
Join Date: Nov 2005
Location: Reeds Springs, Missouri
Posts: 250
Default Re: Billing Changes

Thanks
__________________
sudo rm -rf /mnt/win32 ; sync ; dd if=/dev/random of=/mnt/win32/ooops bs=16384 ; sync
"Knowledge is Power, power corrupts, corruption is illegal. STOP LEARNING BEFORE YOU END UP IN JAIL!"
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

All times are GMT -5. The time now is 06:28 AM.