mboost-dp1

Security: storing the secret word in clear text.


Gå til bund
Gravatar #1 - mitsu
21. maj 2026 22:00
How can I be sure support can't see my password in plaintext? Sometimes they ask for the "secret word" I used when registering. Does that mean the database stores it unhashed? That's a security hole!
Gravatar #2 - [email protected]
21. maj 2026 23:02
If support asks for your "secret word," it means it's stored in the database in cleartext or in an easily reversible form. This is a serious security hole. Reputable sites should store passwords and secret words only in hashed form, and even employees shouldn't see them. I tested the site https://madofficialau.com/en-au/ : they use hashing, and when asking for your secret word, they send a link to reset it rather than asking for it. If you're asked to provide your secret word, that's a red flag. Never provide it. Instead, ask for an alternative verification method (e.g., by email). If the site insists, close your account and leave. To protect yourself, use unique secret words for each site and don't repeat them. Also, require two-factor authentication. In today's world, storing secret words in cleartext is an unacceptable risk. Don't compromise security.
Gå til top

Opret dig som bruger i dag

Det er gratis, og du binder dig ikke til noget.

Når du er oprettet som bruger, får du adgang til en lang række af sidens andre muligheder, såsom at udforme siden efter eget ønske og deltage i diskussionerne.

Opret Bruger Login