> One of the most frequently seen security vulnerabilities
> on the internet today is a web application that will email
> you your password in plaintext.

Speaking of...  A quick rant here...

Went to MAX this year.  Got my registration packet and looked as my session
summary.  As they have done in the past few years, my MAX username and
password were printed in plaintext at the bottom of the page.  I mention
this to the registration desk people every year, maybe they can't change
it...

So...  Some printshop someplace in Boston or San Fran probably has several
thousand passwords stored on a disk someplace (likely not stored in a secure
location).  Any attendees who didn't show up probably had their password
information tossed into a dumpster.  Attendees who didn't notice their
password probably left the sheet in lots of insecure places over the course
of the event, typically holding it in plain sight between sessions looking
at their schedule.  Who knows where that sheet is now.

The sheet isn't the only thing with my password on it.  I also got emails
from Macromedia with my password on them, in plaintext, without my request.
Who knows how many places attendee passwords are floating around out
there....

Perhaps I am a little paranoid, but this really bothers me alot.

-Cameron

-----------------
Cameron Childress
Sumo Consulting Inc.
---
cell:  678.637.5072
land:  858.509.3098
aim:   cameroncf
email: [EMAIL PROTECTED]
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

Reply via email to