[180150] in North American Network Operators' Group
Re: gmail security is a joke
daemon@ATHENA.MIT.EDU (Scott Howard)
Tue May 26 16:10:11 2015
X-Original-To: nanog@nanog.org
In-Reply-To: <CAEE+rGqi0UiC=mEBOcUMFBbBLfSgVKHpmSFw=PE45emxB1cYDQ@mail.gmail.com>
Date: Tue, 26 May 2015 13:10:08 -0700
From: Scott Howard <scott@doc.net.au>
To: "Aaron C. de Bruyn" <aaron@heyaaron.com>
Cc: John Levine <johnl@iecc.com>, NANOG mailing list <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org
On Tue, May 26, 2015 at 12:28 PM, Aaron C. de Bruyn <aaron@heyaaron.com>
wrote:
>
> If they can e-mail you your existing password (*cough*Netgear*cough*),
> it means they are storing your credentials in the database
> un-encrypted.
>
No, it doesn't mean that at all. It means they are storing it unhashed
which is probably what you mean.
It may well be that they are storing it unencrypted, but you can't outright
say that without extra knowledge.
Scott