Security 101
Security 101
Note to @…..
I take great pride in the fact that I evaluate technology platforms before offering them to my customers and I do this with my IT security expert hat on, which seems the correct thing to do given we live in an online world and we offer security solutions.
So imagine my dismay when one of our suppliers switches to a technology platform which I previously rejected because they failed the ‘security 101’ test, part of which is emailing my login password in plain text.
I don’t usually name and shame but in this case the vendor in question is getting considerable traction in the market and this really is basic stuff. It needs fixing now.
The question has to be. If they are sending passwords in plain text then what confidence do I or my customers have that they can secure my archived email.
Here’s the email.
From: noreply@archive….
Date: 2 November 2011 7:53:08 AM GMT
To: ….@cleartext.com
Subject: [Archive System] Password Reset!
Reply-To: noreply@archive….
David, your password has been reset to [removed by me:)]

