Author Topic: Question about security of user data - Passwords stored in cleartext?  (Read 15183 times)

QuickQuestion

  • Guest
Hello,

I've recently become interested in picking up a VPN service, and BolehVPN came highly recommended. I'm liking what I see about the service so far, and I was prepared to purchase at least a few months of the service! I made an account in preparation of the purchase, but was positively shocked when the confirmation email sent me back my password, login, and account number in cleartext. This is a huge security no-no, and I would expect at the very least that the passwords would be stored hashed and salted. It makes me very uncomfortable about divulging payment and address information, even if that is handled through PayPal. 
 
Even overlooking the security of the payment information, given the rash of recent hacks which have occurred the world over to many big name websites and services, I would hope that Boleh would take the security of it's user data seriously. Are there any plans to implement hashing or salting of the passwords any time in the future? Or am I overreacting because the accounts made with this information aren't sensitive? Obviously users never want to have their passwords stolen, but I'm wondering if it's intended for everyone to make 'throw away' accounts. 
 
Thanks for your consideration.

Offline AJaydono

  • BolehVPN Staff
  • Lieutenant
  • *****
  • Posts: 161
Re: Question about security of user data - Passwords stored in cleartext?
« Reply #1 on: December 17, 2011, 02:46:45 PM »
We are looking into it. Yes, we had few suggestions from our customers too. Thank you.

Offline Reuben

  • Chief Doraemon
  • Administrator
  • Admiral
  • *****
  • Posts: 6878
Re: Question about security of user data - Passwords stored in cleartext?
« Reply #2 on: December 17, 2011, 05:39:38 PM »
This will be in our next iteration of our admin system due in the next 2 months or earlier
*If you like my service/support, please consider posting a positive feedback here*<3



Co-Founder/Administrator

Offline Reuben

  • Chief Doraemon
  • Administrator
  • Admiral
  • *****
  • Posts: 6878
Re: Question about security of user data - Passwords stored in cleartext?
« Reply #3 on: December 27, 2011, 10:26:35 AM »
Also just to add quickly, our order site is secured with https so it's not so simple to 'intercept' passwords. It's already secured using https via a VERIFIED SSL certificate. In any case you always send your passwords in cleartext if there is no https protection. We will however implement it to beef up security but as it is, it is already secure UNLESS our server gets hacked into.
*If you like my service/support, please consider posting a positive feedback here*<3



Co-Founder/Administrator

agbgcg

  • Guest
Re: Question about security of user data - Passwords stored in cleartext?
« Reply #4 on: March 04, 2012, 12:56:23 AM »
Just curious, has this been addressed? It's been 2 months, thanks

Offline Reuben

  • Chief Doraemon
  • Administrator
  • Admiral
  • *****
  • Posts: 6878
Re: Question about security of user data - Passwords stored in cleartext?
« Reply #5 on: March 05, 2012, 09:23:01 AM »
The new portal is already undergoing testing, we're just working out the bugs and want to reduce as many mishaps as possible.
*If you like my service/support, please consider posting a positive feedback here*<3



Co-Founder/Administrator

Offline Reuben

  • Chief Doraemon
  • Administrator
  • Admiral
  • *****
  • Posts: 6878
Re: Question about security of user data - Passwords stored in cleartext?
« Reply #6 on: April 13, 2012, 02:59:15 PM »
Anyway new portal is up with encryption of passwords in place.
*If you like my service/support, please consider posting a positive feedback here*<3



Co-Founder/Administrator