Go Back   HostGator Peer Support Forums > Public Forums > Suggestions

Notices

Reply
 
Thread Tools
  #1  
Old 06-02-2008, 06:58 AM
softwarecandy's Avatar
softwarecandy softwarecandy is offline
Junior Croc
 
Join Date: May 2008
Location: Vermont, USA
Posts: 198
Lightbulb Please Stop Emailing me my Password in CLEAR TEXT

So far I am very impressed with HostGator's quality and responsiveness of service.

Except for one issue: security.

When I first registered to HostGator, I was surprised to see in the welcome email, along with my account username, my password - in CLEAR TEXT...

I am not a security expert, but I do know that sensitive/confidential information should always be delivered encrypted (usually over SSL), or by some other semi-secure means (telephone, sealed envelope, etc.).

How can a respectable company like HostGator, which is supposed to host e-commerce sites, can send passwords in clear text?

When I asked HG's support about this, I was told that HostGator is planning to address this issue. However, I didn't receive any specifics or time frame for implementing a solution to this well known problem (which every web site with accounts must face, including my future online store).

"Well", I thought, "if this happens only once, when the account is first established, I can probably live with that since I can change the password immediately".

But then, a few minutes ago, when I ordered a dedicated IP address, I received in the "IP request" confirmation email with... my password again. :-(
It is at the bottom of the email message, along with the ticket ID.

What is going on? How am I supposed to install a shopping cart with a private SSL certificate on a host that delivers my admin password in clear text?

And when is HostGator going to change this?


Last edited by softwarecandy; 06-10-2008 at 07:00 AM. Reason: No need to repeat my request :-)
Reply With Quote
  #2  
Old 06-02-2008, 07:30 AM
Serra's Avatar
Serra Serra is offline
Veteran Croc
 
Join Date: Feb 2005
Location: Orange Park, FL
Posts: 5,067
Default Re: Please Stop Emailing me my Password in CLEAR TEXT

This is a common practice in the hosting industry. Due to the amount of email being passed now days, clear text passwords are no longer an issue as hackers no longer parse email for passwords, just not productive.
__________________
Six stages of Dedi Ownership

Fashionable broken link
image included
Reply With Quote
  #3  
Old 06-02-2008, 09:09 AM
Kris Siegel Kris Siegel is offline
Hatchling Croc
 
Join Date: May 2008
Posts: 31
Default Re: Please Stop Emailing me my Password in CLEAR TEXT

Quote:
Originally Posted by Serra View Post
This is a common practice in the hosting industry. Due to the amount of email being passed now days, clear text passwords are no longer an issue as hackers no longer parse email for passwords, just not productive.
I think the biggest issue is the fact that HostGator is storing passwords as either clear text or encrypted text. Both are common but very bad practice.

Any website that requires the users to create and use a password should always store the password in a salted hash. Anything else, IMO, is gross negligence. Even encrypting the password is bad as the company holding the encrypted passwords can easily decrypt them.

While sending passwords in an e-mail isn't a good idea I think the way HostGator is / was storing passwords is the bigger issue.

I'm curious to know if their new solution is simply encrypted passwords or if they've doing it right this time with hashed passwords.
Reply With Quote
  #4  
Old 06-10-2008, 06:49 AM
softwarecandy's Avatar
softwarecandy softwarecandy is offline
Junior Croc
 
Join Date: May 2008
Location: Vermont, USA
Posts: 198
Thumbs up Re: Please Stop Emailing me my Password in CLEAR TEXT

Quote:
Originally Posted by Kris Siegel View Post
I think the biggest issue is the fact that HostGator is storing passwords as either clear text or encrypted text. Both are common but very bad practice.

Any website that requires the users to create and use a password should always store the password in a salted hash. Anything else, IMO, is gross negligence. Even encrypting the password is bad as the company holding the encrypted passwords can easily decrypt them.

While sending passwords in an e-mail isn't a good idea I think the way HostGator is / was storing passwords is the bigger issue.
Well, I just consulted with a professional in this business and he agrees with you. This is what he says:

Quote:
HostGator is obviously storing passwords in cleartext or in some method where the cleartext can easily be recovered. If they have a break-in, or a rogue employee, the entire password file might get disclosed. That is not "industry best practice" and they should know better.
That said, I believe that HostGator strives to excel in its business and I hope that it will address this issue before such breach occurs. I would be glad to learn that HostGator indeed intends to address this issue (just as it is doing now in its billing system).

Reply With Quote
  #5  
Old 06-10-2008, 07:17 AM
striddy striddy is offline
Emperor Croc
 
Join Date: Mar 2008
Location: /home/australia/earth
Posts: 2,978
Default Re: Please Stop Emailing me my Password in CLEAR TEXT

You can and should be changing your passwords often.

See this recent thread.

http://forums.hostgator.com/showthread.php?t=33655
__________________
- David

Folding@Home Stats :
Reply With Quote
  #6  
Old 06-10-2008, 08:22 AM
softwarecandy's Avatar
softwarecandy softwarecandy is offline
Junior Croc
 
Join Date: May 2008
Location: Vermont, USA
Posts: 198
Default Re: Please Stop Emailing me my Password in CLEAR TEXT

Quote:
Originally Posted by striddy View Post
You can and should be changing your passwords often.
I agree and indeed that's what I do.

However, I would like to be able to set the schedule for changing my passwords (e.g once every X months, just like employees in large Hi-Tech corporations are required to do) and not upon a surprise after every minor communication with HostGator.

Quote:
Originally Posted by striddy View Post


I noticed your question:

Quote:
Originally Posted by striddy View Post
And how would you prefer they email you the passwords?

Passwords from any site you join on the web are always sent in plain old email.
Actually, this depends on the institution and type of account involved. My bank, for example, would never email me my password. Instead, I have to call a representative and get my password over the phone.

But I am not expecting this level of security from HostGator. This may be an overkill for this kind of account. What I do expect is that my password will be emailed to me, only upon my initiated request. That way, it is reasonable to assume that I am in that "special mode" of immediately changing my just-emailed password (like what happens when you first register to almost any password protected web based service).

BTW, HostGator has multiple types of accounts, each allowing a different userid/password:
  1. cPanel (web site admin and maintenance)
  2. Billing
  3. Support (ticket system)
  4. Forums
The first two are more sensitive to password protection practices then the last two. IMHO, HostGator doesn't have to deal with all of these issues at the same time or give them the same priority.

Reply With Quote
  #7  
Old 06-15-2008, 05:03 AM
dustbuster dustbuster is offline
Hatchling Croc
 
Join Date: Feb 2008
Posts: 12
Default Re: Please Stop Emailing me my Password in CLEAR TEXT

It is worrying that they even have access to our non-hashed passwords. I seem to recall writing to support about this, and their response was that it's more convenient for customers to keep emailing passwords in cleartext.
Reply With Quote
  #8  
Old 06-15-2008, 11:06 AM
vince vince is offline
Hatchling Croc
 
Join Date: May 2008
Posts: 23
Default Re: Please Stop Emailing me my Password in CLEAR TEXT

Quote:
Originally Posted by dustbuster View Post
It is worrying that they even have access to our non-hashed passwords. I seem to recall writing to support about this, and their response was that it's more convenient for customers to keep emailing passwords in cleartext.
What they should be doing is storing passwords in a 1 way hash format like MD5. The original password cannot be recovered (at least in a reasonable amount of time, yes over 5 years you might bang a password out), that's the point.

Passwords should never be emailed, instead a single use link to a website (encrypted with SSL) should be used to reset the password.

HostGator had a potential security breach with an exiting employee last month: http://forums.hostgator.com/showthread.php?t=33170&

Can anyone from HG chime in an let us know when our data will not be plain text?
Reply With Quote
  #9  
Old 11-22-2009, 03:48 AM
n0rbertt n0rbertt is offline
Hatchling Croc
 
Join Date: Nov 2009
Posts: 1
Default Re: Please Stop Emailing me my Password in CLEAR TEXT

I would think they are emailed to you and then md5'd for the DB , no ?
Reply With Quote
  #10  
Old 11-26-2009, 07:31 PM
Major Internet Major Internet is offline
Hatchling Croc
 
Join Date: Nov 2009
Posts: 18
Default Re: Please Stop Emailing me my Password in CLEAR TEXT

Are we talking about shared account or all accounts?

If on a shared account, I would think that the cost involved re-authing hashed passwords would be cost prohibitive. I know for a fact I don't try to recall passwords as I choose not to record them for security. That means the 2-6 months I spend not using a particular account password means I have to retrieve it.

That being said, I log into the account and change the password on my way out using the generator. Pretty sure thats why it's there

Reseller Primary WHM accounts should be hashed.
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Clear text passwords in e-mail communications akabani Suggestions 0 10-30-2006 09:44 AM

All times are GMT -6. The time now is 10:33 AM.