Go Back   HostGator Peer Support Forums > HostGator Peer Support Forums > Shared Hosting Support

Notices

Reply
 
Thread Tools
  #1  
Old 05-23-2008, 11:03 AM
nd4spd nd4spd is offline
Hatchling Croc
 
Join Date: Apr 2005
Posts: 12
Default Password change email?

I just received an email supposed to have come from Hostgator. It reads in part:

Quote:
Dear XXXX,
We've recently have done an audit of HostGator's web hosting services and have found that
many of our customers have a weak password.

In an attempt to secure your hosting further we have changed all of our customers
passwords to a randomly generated password that meets our guidelines .

In order to obtain your new password please click the following link:


https://secure.hostgator.com/password_reset/



How do you know this is from HostGator?

1. We put your name in the email.
2. Mouse over the url and it is in fact https://secure.hostgator.com
3. Try logging into your account and you will notice the password has been changed.
My question: Did you really send this? Reason being, the person it was sent to is not me (not even close). Also, what's to ensure everyone sees this email. Wouldn't an announcement or a message on the login screen be more appropriate?

Regards,
Aaron
Reply With Quote
  #2  
Old 05-23-2008, 11:06 AM
csl csl is offline
Hatchling Croc
 
Join Date: Jun 2005
Posts: 4
Default Re: Password change email?

Yep, I got this -- currently chatting to support about it.
Reply With Quote
  #3  
Old 05-23-2008, 11:08 AM
nd4spd nd4spd is offline
Hatchling Croc
 
Join Date: Apr 2005
Posts: 12
Default Re: Password change email?

Let me know how that works out. Frankly, this was a really poor way to handle something like this.
Reply With Quote
  #4  
Old 05-23-2008, 11:15 AM
csl csl is offline
Hatchling Croc
 
Join Date: Jun 2005
Posts: 4
Default Re: Password change email?

Okay -- filled in the form, and although nothing appeared to happen, I then received a new password via email. Not a very clear process though -- I couldn't tell if the form had worked or not.
Reply With Quote
  #5  
Old 05-23-2008, 11:15 AM
Papajin Papajin is offline
Hatchling Croc
 
Join Date: Mar 2005
Posts: 2
Default Re: Password change email?

I received one as well, and agree whole-heartedly. Unless there was some pressing reason to make an emergency password change, you don't just go and make a change spur of the moment without letting folks know. Would an email a week in advance have been so hard?

Hostgator is no longer some tiny host being run out of a dorm room (I hope) any longer -- let's start seeing some customer service that indicates this is the case... It shouldn't take a genius to see that a change like this is going to impact a HUGE number of people and realize it would be wise to give them a small amount of time to both prepare for the change as well as let us all know it's not a scam email in advance.

It appears to be valid btw. I can't get into my control panel or the main ftp account with the old password. I browsed the email source as well and it appeared to be valid - all links pointed where they should have.
Reply With Quote
  #6  
Old 05-23-2008, 11:23 AM
nd4spd nd4spd is offline
Hatchling Croc
 
Join Date: Apr 2005
Posts: 12
Default Re: Password change email?

Papajin,

Yes, I checked source and links as well. And you are correct, this is NOT the way to handle it. Besides, if they want secure they shouldn't be sending passwords via email anyway.

Nice job HG. Throw this right before a (US) holiday weekend. Thanks.
Reply With Quote
  #7  
Old 05-23-2008, 12:21 PM
gwyneth's Avatar
gwyneth gwyneth is offline
Supreme Croc
 
Join Date: Sep 2006
Location: up north
Posts: 6,843
Default Re: Password change email?

Quote:
Originally Posted by nd4spd View Post
Papajin,

Yes, I checked source and links as well. And you are correct, this is NOT the way to handle it. Besides, if they want secure they shouldn't be sending passwords via email anyway.

Nice job HG. Throw this right before a (US) holiday weekend. Thanks.
This thread appears to have prompted an announcement in the Host Gator Announcement category...which would be both after the fact and unnoticed by many customers.

The "all customers" bit is followed by "if yours has been reset..." which at the least is contradictory.

If it's really ALL customers, I predict massive unintended consequences and support traffic jams...very poorly thought out, if ALL were changed at once.
Reply With Quote
  #8  
Old 05-23-2008, 01:03 PM
Serra's Avatar
Serra Serra is offline
Veteran Croc
 
Join Date: Feb 2005
Location: Orange Park, FL
Posts: 5,073
Default Re: Password change email?

Quote:
Originally Posted by nd4spd View Post
Yes, I checked source and links as well. And you are correct, this is NOT the way to handle it. Besides, if they want secure they shouldn't be sending passwords via email anyway.

Nice job HG. Throw this right before a (US) holiday weekend. Thanks.

I'm fairly sure that Brent didn't wake up this morning and say, "Hey, lets just screw everyone!". I imagine there is a good reason they are doing this.

Edit: I'm guessing that the system will not accept crap passwords any more too.
__________________
Six stages of Dedi Ownership

Fashionable broken link
image included

Last edited by Serra; 05-23-2008 at 01:07 PM.
Reply With Quote
  #9  
Old 05-23-2008, 02:57 PM
nd4spd nd4spd is offline
Hatchling Croc
 
Join Date: Apr 2005
Posts: 12
Default Re: Password change email?

Quote:
Originally Posted by Serra View Post
I'm fairly sure that Brent didn't wake up this morning and say, "Hey, lets just screw everyone!". I imagine there is a good reason they are doing this.

Edit: I'm guessing that the system will not accept crap passwords any more too.
I'm sure he didn't. However the lack of testing or notification bothers me. I've received 3 or 4 of these notices and not ONE has had the correct name on it. In my opinion it is just slack and not well planned out.
Reply With Quote
  #10  
Old 05-23-2008, 03:02 PM
nd4spd nd4spd is offline
Hatchling Croc
 
Join Date: Apr 2005
Posts: 12
Default Re: Password change email?

Oh, this is great security. Since I've several domains under one account email address it has set the passwords for multiple accounts to the same password! I hardly see how this is secure.

For example:
email_address@tld.com
|__> www.account1.com
|__> www.account2.com

Reset password for account 1, password works for account 1 AND 2
Reply With Quote
  #11  
Old 05-23-2008, 03:29 PM
gwyneth's Avatar
gwyneth gwyneth is offline
Supreme Croc
 
Join Date: Sep 2006
Location: up north
Posts: 6,843
Default Re: Password change email?

Quote:
Originally Posted by Serra View Post
I'm fairly sure that Brent didn't wake up this morning and say, "Hey, lets just screw everyone!". I imagine there is a good reason they are doing this.

Edit: I'm guessing that the system will not accept crap passwords any more too.
Of course he didn't. But "all" is a pretty big genie to let out of a bottle...at both ends (the customers and HG support).

Presumably this means even folks with secure passwords got changed?
Reply With Quote
  #12  
Old 05-23-2008, 07:10 PM
Serra's Avatar
Serra Serra is offline
Veteran Croc
 
Join Date: Feb 2005
Location: Orange Park, FL
Posts: 5,073
Default Re: Password change email?

Quote:
Originally Posted by gwyneth View Post
Presumably this means even folks with secure passwords got changed?
As I pointed out in the other tread, HG can't know what people's cPanel passwords are, they aren't recoverable. Discovering that HG could determine people's cPanel passwords would be enough to send me into a coma, as that would mean that cPanel has a major security flaw. (Not like it doesn't have one every other week, but we've had this weeks flaw already, haven't we?)
__________________
Six stages of Dedi Ownership

Fashionable broken link
image included
Reply With Quote
  #13  
Old 05-23-2008, 07:43 PM
Kazper Kazper is offline
Hatchling Croc
 
Join Date: May 2008
Location: Denmark
Posts: 24
Default Re: Password change email?

Argh. I HATE companies and programs that try to tell me what a secure password is. I have a 12 digit long pwd with a combination of upper and lowercase, numbers and special chars. And it STILL rejects it because apparently 4 of those letters (mixed case) put together forms a "dictionary" word in English.

Quite aside from the spelling errors, the phishing similarities, the WRONG name in the mail, and the requirement of apparently using my first pwd - that simple fact is enough to aggravate me to hell and back. I get enough of that crap from the sysadmins at my work that forces you to use 5 different pwds with varying demands.

Way to mess things up!
Reply With Quote
  #14  
Old 05-23-2008, 10:21 PM
wllow wllow is offline
Hatchling Croc
 
Join Date: Jul 2004
Posts: 1
Default Re: Password change email?

I have to agree. If you want to convince someone that this is not a phishing email, at least get the customer's name right. And FYI, just "mousing over the URL" isn't proof enough that the URL is not faked - with HTML email, Javascript, AJAX, and all that dynamic stuff, you cannot trust that to be right. Add to it the fact that I'm seeing the email come from "HostGator@yahoo.com" (I received this at my Yahoo! email) doesn't increase my confidence either.
Reply With Quote
  #15  
Old 05-23-2008, 10:47 PM
Grumpy Grumpy is offline
Hatchling Croc
 
Join Date: Sep 2004
Posts: 11
Default Re: Password change email?

sticky thread on this
http://forums.hostgator.com/showthread.php?t=33155
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Cant change my password Apocalypsse Shared Hosting Support 1 04-15-2008 02:55 AM
Change MySQL Password? mjbanks Shared Hosting Support 5 11-01-2006 06:49 PM

All times are GMT -5. The time now is 09:26 PM.