<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Bluehost stores your password in plain text</title>
	<atom:link href="http://yanpritzker.com/2008/07/10/bluehost-stores-your-password-in-plain-text/feed/" rel="self" type="application/rss+xml" />
	<link>http://yanpritzker.com/2008/07/10/bluehost-stores-your-password-in-plain-text/</link>
	<description>photographer, entrepreneur, software engineer, musician, skier</description>
	<lastBuildDate>Sat, 04 Sep 2010 20:29:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Ritesh Nadhani</title>
		<link>http://yanpritzker.com/2008/07/10/bluehost-stores-your-password-in-plain-text/comment-page-1/#comment-42824</link>
		<dc:creator>Ritesh Nadhani</dc:creator>
		<pubDate>Fri, 07 May 2010 19:10:46 +0000</pubDate>
		<guid isPermaLink="false">http://skwpspace.com/?p=176#comment-42824</guid>
		<description>Nope. They keep in plain passoword. I just did forgot password and they sent me the password in plain text.</description>
		<content:encoded><![CDATA[<p>Nope. They keep in plain passoword. I just did forgot password and they sent me the password in plain text.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yan</title>
		<link>http://yanpritzker.com/2008/07/10/bluehost-stores-your-password-in-plain-text/comment-page-1/#comment-40575</link>
		<dc:creator>yan</dc:creator>
		<pubDate>Sun, 14 Mar 2010 19:00:42 +0000</pubDate>
		<guid isPermaLink="false">http://skwpspace.com/?p=176#comment-40575</guid>
		<description>Unbelievable...such a prominent web host can&#039;t follow basic password security? How do we bring more attention to this? I tried posting on the CEO&#039;s blog and no response...</description>
		<content:encoded><![CDATA[<p>Unbelievable&#8230;such a prominent web host can&#8217;t follow basic password security? How do we bring more attention to this? I tried posting on the CEO&#8217;s blog and no response&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stinga</title>
		<link>http://yanpritzker.com/2008/07/10/bluehost-stores-your-password-in-plain-text/comment-page-1/#comment-40567</link>
		<dc:creator>stinga</dc:creator>
		<pubDate>Sun, 14 Mar 2010 16:39:41 +0000</pubDate>
		<guid isPermaLink="false">http://skwpspace.com/?p=176#comment-40567</guid>
		<description>Nope, they still store in plain text, I know this because they just sent it to me!
Only 8 more domains and we will no longer be giving Bluehost any money.. yaaaa!

BTW: Any service that offers a &#039;forgot your password&#039; store password unencrypted, if they offer to reset it then the store encrypted (maybe)</description>
		<content:encoded><![CDATA[<p>Nope, they still store in plain text, I know this because they just sent it to me!<br />
Only 8 more domains and we will no longer be giving Bluehost any money.. yaaaa!</p>
<p>BTW: Any service that offers a &#8216;forgot your password&#8217; store password unencrypted, if they offer to reset it then the store encrypted (maybe)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yan</title>
		<link>http://yanpritzker.com/2008/07/10/bluehost-stores-your-password-in-plain-text/comment-page-1/#comment-40538</link>
		<dc:creator>yan</dc:creator>
		<pubDate>Sat, 13 Mar 2010 23:39:53 +0000</pubDate>
		<guid isPermaLink="false">http://skwpspace.com/?p=176#comment-40538</guid>
		<description>I am curious how this new functionality works. In order to compare 4 characters of your password wouldn&#039;t they still have to have the plaintext password? If they were storing your password as they should, encrypted with a one way hash function there would be no way (as far as I know) for them to verify 4 chars of the password, unless they were also storing the last 4 characters separately hashed. 

It would be great to hear directly from bluehost on how they do store your password now, however as with all other things they never tell customers what they are doing, never own up to any problems, and prefer to fix things quietly and secretly. So maybe they did fix this, but they sure didn&#039;t tell the world (imagine how many people would be up in arms if they actually knew and understood the ramifications of having their password stored plaintext and known by any support employee).</description>
		<content:encoded><![CDATA[<p>I am curious how this new functionality works. In order to compare 4 characters of your password wouldn&#8217;t they still have to have the plaintext password? If they were storing your password as they should, encrypted with a one way hash function there would be no way (as far as I know) for them to verify 4 chars of the password, unless they were also storing the last 4 characters separately hashed. </p>
<p>It would be great to hear directly from bluehost on how they do store your password now, however as with all other things they never tell customers what they are doing, never own up to any problems, and prefer to fix things quietly and secretly. So maybe they did fix this, but they sure didn&#8217;t tell the world (imagine how many people would be up in arms if they actually knew and understood the ramifications of having their password stored plaintext and known by any support employee).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roger Brown</title>
		<link>http://yanpritzker.com/2008/07/10/bluehost-stores-your-password-in-plain-text/comment-page-1/#comment-40534</link>
		<dc:creator>Roger Brown</dc:creator>
		<pubDate>Sat, 13 Mar 2010 19:46:30 +0000</pubDate>
		<guid isPermaLink="false">http://skwpspace.com/?p=176#comment-40534</guid>
		<description>For what its worth, that has since changed. Now their support can ask for the last 4 of the password, enter it into a form, and then it reports whether it was correct or not.</description>
		<content:encoded><![CDATA[<p>For what its worth, that has since changed. Now their support can ask for the last 4 of the password, enter it into a form, and then it reports whether it was correct or not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bookmarks about Ruby</title>
		<link>http://yanpritzker.com/2008/07/10/bluehost-stores-your-password-in-plain-text/comment-page-1/#comment-15082</link>
		<dc:creator>Bookmarks about Ruby</dc:creator>
		<pubDate>Wed, 01 Oct 2008 09:45:13 +0000</pubDate>
		<guid isPermaLink="false">http://skwpspace.com/?p=176#comment-15082</guid>
		<description>[...] - bookmarked by 4 members originally found by Aoi on 2008-09-11  Bluehost stores your password in plain text  http://skwpspace.com/2008/07/10/bluehost-stores-your-password-in-plain-text/ - bookmarked by 4 [...]</description>
		<content:encoded><![CDATA[<p>[...] &#8211; bookmarked by 4 members originally found by Aoi on 2008-09-11  Bluehost stores your password in plain text  <a href="http://skwpspace.com/2008/07/10/bluehost-stores-your-password-in-plain-text/" rel="nofollow">http://skwpspace.com/2008/07/10/bluehost-stores-your-password-in-plain-text/</a> &#8211; bookmarked by 4 [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.240 seconds -->
