<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html" />
  <link rel="self" type="application/atom+xml" href="http://ask-leo.com/atom.xml" />
  <id>tag:ask-leo.com,2011://3/tag:ask-leo.com,2010://3.4376-</id>
  <updated>2011-11-22T22:59:19Z</updated>
  <title>Comments for Why won&apos;t services just email me my password instead of making me set a new one?</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.32-en</generator>

  <entry>
    <id>tag:ask-leo.com,2010://3.4376-comment:61792</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2010://3.4376" type="text/html" href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html#c61792" />
    <title>Comment from Toy Trumpet on 2011-11-21</title>
    <author>
      <name>Toy Trumpet</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>There is a site called http://plaintextoffenders.com/ which names and shames this type of password insecurity.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html">Why won&apos;t services just email me my password instead of making me set a new one?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2011</a>.</p>
    </content>
    <published>2011-11-21T17:46:42Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2010://3.4376-comment:49338</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2010://3.4376" type="text/html" href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html#c49338" />
    <title>Comment from john on 2010-08-10</title>
    <author>
      <name>john</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>That's really interesting and well explained. Thank you. But I'd be interested, and grateful, if you could take it a step further and explain what is going on with those sites (mostly banks, I find) that ask for (say) the 3rd, 5th and 10th character of your password, which cannot generate the same hash as the full password.<br />
<div class="leocomment">I've never seen that, however: it could be that they're storing your password (which would be bad), or perhaps when you set your password they save the 3rd, 5th and 10th characters only for later comparisons. That doesn't store your password, but it also doesn't compromise a sufficiently strong password either.<br />
<div class="leocommentsig"><img src="http://img.askleomedia.com/leo2t.png" alt="Leo" /><br /><span class="leocommentdate">14-Aug-2010</span></div></div><br />
</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html">Why won&apos;t services just email me my password instead of making me set a new one?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2010</a>.</p>
    </content>
    <published>2010-08-10T16:45:28Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2010://3.4376-comment:49087</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2010://3.4376" type="text/html" href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html#c49087" />
    <title>Comment from James on 2010-08-02</title>
    <author>
      <name>James</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>"They don't know your password, they didn't store your password, and they couldn't tell you if they wanted to." <br />
I have been saying to anyone who'd listen, probably for 30 years, that this ought to be true. But to my consternation I've recently had proof that it isn't, because www.guardian.co.uk actually emailed my password to me. </p>

<p>Admittedly, this is a free registration site, and doesn't claim to be secure, but that's not much of an excuse.</p>

<p>So Hey, let's be careful out there!</p>

<div class="leocomment">Yeah, there are sites that do, and as I said in the article - if they can mail you your password, they're doing security <strong>wrong</strong>. (I had one emailed to me just yesterday from aother site. Sigh.)
<div class="leocommentsig"><img src="http://img.askleomedia.com/leo2t.png" alt="Leo" /><br /><span class="leocommentdate">03-Aug-2010</span></div></div>
]]>
      <p>A comment on: <a href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html">Why won&apos;t services just email me my password instead of making me set a new one?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2010</a>.</p>
    </content>
    <published>2010-08-02T16:14:46Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2010://3.4376-comment:48937</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2010://3.4376" type="text/html" href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html#c48937" />
    <title>Comment from pentester on 2010-07-27</title>
    <author>
      <name>pentester</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>[<b>" Had the passwords not been stored, but instead a hash used, then the hacker would have next to nothing."</b>]</p>

<p>I beg the differ ... It is a one way street in so many ways yes, but so many it isn't.  Depending on the power of you computer, the size of your rainbow tables, and the willing time, cracking 80% of a password database could be done within a few weeks.  The 1st day would weed out approx. 50% due to the week dictionary passwords that a simple dictionary attack could crack.<br />
<div class="leocomment">Which is why random unique passwords are so critical. They won't be in the tables.<br />
<div class="leocommentsig"><img src="http://img.askleomedia.com/leo2t.png" alt="Leo" /><br /><span class="leocommentdate">29-Jul-2010</span></div></div><br />
</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html">Why won&apos;t services just email me my password instead of making me set a new one?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2010</a>.</p>
    </content>
    <published>2010-07-27T22:52:26Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2010://3.4376-comment:48893</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2010://3.4376" type="text/html" href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html#c48893" />
    <title>Comment from Carl R. Goodwin on 2010-07-27</title>
    <author>
      <name>Carl R. Goodwin</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>It probably took longer to write the question than it would have to just reset the password!!!</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/why_wont_services_just_email_me_my_password_instead_of_making_me_set_a_new_one.html">Why won&apos;t services just email me my password instead of making me set a new one?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2010</a>.</p>
    </content>
    <published>2010-07-27T15:25:50Z</published>
  </entry>

</feed>

