Recommended Posts

Went to try and purchase the Battlefield Bad Company 2: Vietnam expansion that was on sale today from Direct 2 Drive. For whatever reason, they weren't able to process my order, so my friend decided to gift it to me instead. When I got the e-mail, imagine my surprise when I saw this:

ZOvSt.png

They E-Mailed me my account password in paintext! What does this mean? My username, password and any related information to that account are all stored in a database - unencrypted. :angry:

Shocking, especially given the amount of news compromised databases this year.

Link to comment
https://www.neowin.net/forum/topic/992392-really-direct-2-drive-really/
Share on other sites

That, my friend is ridiculous. I never really checked out D2D as I was never a huge PC gamer, but is there a reason you do not use Steam? I doubt Valve would allow this type of behavior.

I use and adore Steam. The expansion was on sale though, and I'm cheap (I bought BFBC2 when it was on sale through the EA store).

D2D being a store that deals with financial transactions, I had assumed that they'd be a little more responsible with my data though.

I would still say that the data will be encrypted, but it will be 2-way encryption, instead of doing what everyone else does and use a hash. Still, that's pretty apalling to email you your password. I have had websites do that to me as a "forgot your password" reminder, and it still makes me uneasy.

I would still say that the data will be encrypted, but it will be 2-way encryption, instead of doing what everyone else does and use a hash. Still, that's pretty apalling to email you your password. I have had websites do that to me as a "forgot your password" reminder, and it still makes me uneasy.

Well then, maybe I've over-reacted.

However, given that the e-mail was automated, wouldn't that suggest that the pass-phrase / function used to encrypt the password would be found somewhere in the source code? If an attacker were to gain access to the database, then they could also gain access to the back-end code as well.

Well then, maybe I've over-reacted.

However, given that the e-mail was automated, wouldn't that suggest that the pass-phrase / function used to encrypt the password would be found somewhere in the source code? If an attacker were to gain access to the database, then they could also gain access to the back-end code as well.

Actually I don't think you did. When the email was sent, it was still sent (most likely) over an insecure path, free for anyone to intercept along the way.

You should email / call about this. It may not make a difference, but still bring it to their attention.

Yup, opened a support ticket with them to let them know. Hopefully they'll be able to change this behavior.

Man, that's some short password you got there.

It's actually larger than that, I just botched up while doing the redaction. (Note the white space to the right of "You") ;)

It's odd that they'd send you your actual password like that. I wouldn't be too worried though. A lot of services send you a randomly generated password after requesting a new password. I don't think it's any different in terms of security.

It's odd that they'd send you your actual password like that. I wouldn't be too worried though. A lot of services send you a randomly generated password after requesting a new password. I don't think it's any different in terms of security.

They generate the random password, send it to you in an email, then hash it before it is put in the database. It's not retrievable in plain text after this point.

I Think that is suppose to be a temp password, it auto created an account for you so u can login. Whom ever sent you a gift, sent it to a email address that did not have an account.

Sadly, this isn't the case - it was actually my password that I had personally set for that account.

I would bet that more sites that not still haven't learned the benefits of hashing passwords sadly. I wonder too how many of those that have take the time to also salt the password hash.

I hate companies like that, when they send you emails with your ****ing password clear as day in the email.

They say **** like ... Login now with your password and the proceed to tell you in plain text what your ****ing password is. Idiots

Plenty of fish does the same thing

https://www.neowin.net/forum/topic/944688-online-security-at-its-best/

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Ah well, who needs computers in the next 10... 15 years right? At this point is just money laundering.
    • RollerCoaster Tycoon 3 and Voidwrought are free on the Epic Games Store by Pulasthi Ariyasinghe PC gamers can now jump in and grab two more games to keep this week, as the Epic Games Store's ever-present giveaway promotion has just gone through another refresh. Replacing last week's Citizen Sleeper and Robobeat offers, the store has brought in RollerCoaster Tycoon 3 Complete Edition and Voidwrought to keep. From the duo, Roller Coaster Tycoon 3: Complete Edition is an enhanced version of the classic title that was originally released in 2004. It comes with enhancements such as widescreen and 1080p resolution support, as well as increased compatibility with modern PC hardware. It also comes bundled with all the extra content from the Soaked! and Wild! expansion packs. "Control park finances, shops, services and staff to succeed in dozens of scenarios," reads the description. "Become a true tycoon and embark on your promising new career, or create your ideal park without money woes in sandbox mode. Satisfy your guests’ needs and keep your park running smoothly to succeed." If management is not your style, Voidwrought lands as a 2D action-platformer featuring hand-drawn cosmic horrors. The title touts tight platforming and close‑quarters combat, all brought together with a strong emphasis on mobility. "Descend below the star-scorched surface and explore the multidimensional depths below," says the studio Powersnake about the game. "Witness the corrupted revelry of the Court, lose yourself in the icy tunnels of the Old Waters, and discover the grim fate of the Abandoned Expedition." The RollerCoaster Tycoon 3 Complete Edition and Voidwrought giveaways are set to run until June 25 on the Epic Games Store, giving PC gamers seven days to claim the latest offer. Once this closes out, new freebies will take their place on the same day as always. Don't forget that mobile gamers can check out the Epic Game Store's weekly giveaways on Android and iOS to grab a freebie there as well.
    • I have a feeling this memory shortage issues are going to linger 6-8 years so until and unless Chinese memory floods the markets we are doomed
    • If you look at the account logs more than likely it will be showing that the request is coming from Valley Nebraska. we have been seeing thousands of these the last day or so.
  • Recent Achievements

    • First Post
      kinowa earned a badge
      First Post
    • Rookie
      krychek57 went up a rank
      Rookie
    • Grand Master
      Jaybonaut went up a rank
      Grand Master
    • One Year In
      Philsl earned a badge
      One Year In
    • Dedicated
      Scoobystu earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      443
    2. 2
      +Edouard
      169
    3. 3
      PsYcHoKiLLa
      133
    4. 4
      Xenon
      77
    5. 5
      Michael Scrip
      75
  • Tell a friend

    Love Neowin? Tell a friend!