Recommended Posts

Went to try and purchase the Battlefield Bad Company 2: Vietnam expansion that was on sale today from Direct 2 Drive. For whatever reason, they weren't able to process my order, so my friend decided to gift it to me instead. When I got the e-mail, imagine my surprise when I saw this:

ZOvSt.png

They E-Mailed me my account password in paintext! What does this mean? My username, password and any related information to that account are all stored in a database - unencrypted. :angry:

Shocking, especially given the amount of news compromised databases this year.

Link to comment
https://www.neowin.net/forum/topic/992392-really-direct-2-drive-really/
Share on other sites

That, my friend is ridiculous. I never really checked out D2D as I was never a huge PC gamer, but is there a reason you do not use Steam? I doubt Valve would allow this type of behavior.

I use and adore Steam. The expansion was on sale though, and I'm cheap (I bought BFBC2 when it was on sale through the EA store).

D2D being a store that deals with financial transactions, I had assumed that they'd be a little more responsible with my data though.

I would still say that the data will be encrypted, but it will be 2-way encryption, instead of doing what everyone else does and use a hash. Still, that's pretty apalling to email you your password. I have had websites do that to me as a "forgot your password" reminder, and it still makes me uneasy.

I would still say that the data will be encrypted, but it will be 2-way encryption, instead of doing what everyone else does and use a hash. Still, that's pretty apalling to email you your password. I have had websites do that to me as a "forgot your password" reminder, and it still makes me uneasy.

Well then, maybe I've over-reacted.

However, given that the e-mail was automated, wouldn't that suggest that the pass-phrase / function used to encrypt the password would be found somewhere in the source code? If an attacker were to gain access to the database, then they could also gain access to the back-end code as well.

Well then, maybe I've over-reacted.

However, given that the e-mail was automated, wouldn't that suggest that the pass-phrase / function used to encrypt the password would be found somewhere in the source code? If an attacker were to gain access to the database, then they could also gain access to the back-end code as well.

Actually I don't think you did. When the email was sent, it was still sent (most likely) over an insecure path, free for anyone to intercept along the way.

You should email / call about this. It may not make a difference, but still bring it to their attention.

Yup, opened a support ticket with them to let them know. Hopefully they'll be able to change this behavior.

Man, that's some short password you got there.

It's actually larger than that, I just botched up while doing the redaction. (Note the white space to the right of "You") ;)

It's odd that they'd send you your actual password like that. I wouldn't be too worried though. A lot of services send you a randomly generated password after requesting a new password. I don't think it's any different in terms of security.

It's odd that they'd send you your actual password like that. I wouldn't be too worried though. A lot of services send you a randomly generated password after requesting a new password. I don't think it's any different in terms of security.

They generate the random password, send it to you in an email, then hash it before it is put in the database. It's not retrievable in plain text after this point.

I Think that is suppose to be a temp password, it auto created an account for you so u can login. Whom ever sent you a gift, sent it to a email address that did not have an account.

Sadly, this isn't the case - it was actually my password that I had personally set for that account.

I would bet that more sites that not still haven't learned the benefits of hashing passwords sadly. I wonder too how many of those that have take the time to also salt the password hash.

I hate companies like that, when they send you emails with your ****ing password clear as day in the email.

They say **** like ... Login now with your password and the proceed to tell you in plain text what your ****ing password is. Idiots

Plenty of fish does the same thing

https://www.neowin.net/forum/topic/944688-online-security-at-its-best/

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Just what I wanted, an even bigger bomb in my Chinese spy phone.
    • Be sure to toss in a couple tacos to sweeten the deal, no one else sells better bridges!
    • Online didn't launch until October of 2013. So no one could play it. Even then there were issues.
    • Google Finance is now out of beta with improved portfolio tracking and a new Android app by Karthik Mudaliar Google is taking its redesigned Google Finance experience out of beta and adding several new features, including portfolio tracking, scheduled market briefings, and a dedicated Android app. The company says the updates are beginning to roll out globally this week, while an iOS app is planned for later in 2026. The most notable addition is the new portfolio feature. Instead of entering every investment manually, users can upload a screenshot, CSV file, or PDF containing their holdings. They can also tell Google Finance what they own using natural language, such as the number of shares held in a particular company or fund. Google Finance will then place those investments into a dashboard showing performance, asset allocation, concentration risk, and the holdings responsible for the biggest gains or losses. Existing portfolios created with the older version of Google Finance should appear automatically. The built-in AI research panel can use the portfolio as context when answering questions. For example, users can ask which sectors are underrepresented or how their fixed-income allocation could affect long-term growth. Google says portfolio data will remain private and that uploaded files and images will not be retained. Users will also be able to edit or delete their portfolio information after it has been imported. Google Finance is also getting scheduled tasks. These let users request recurring reports such as a daily summary of overnight cryptocurrency movements or a weekly update about newly announced initial public offerings. There is also a new Google Finance app for Android. It includes watchlists, interactive charts, real-time market data, a live news feed, and the same AI research panel available on the web. Google has been gradually expanding the AI-powered Finance redesign since it first entered testing. In April, the experience was expanded to more than 100 countries, bringing its research tools, advanced charts, and market news to a much larger audience. That was followed by a wider European rollout in May, which added features including live earnings calls, transcripts, and AI-generated summaries. The ability to import an entire portfolio from a screenshot or document should make Google Finance considerably easier to set up. However, Android users will have to wait for feature parity with the web version, and Google has yet to say exactly when the iOS app will arrive.
  • Recent Achievements

    • First Post
      kinowa earned a badge
      First Post
    • Rookie
      krychek57 went up a rank
      Rookie
    • Grand Master
      Jaybonaut went up a rank
      Grand Master
    • One Year In
      Philsl earned a badge
      One Year In
    • Dedicated
      Scoobystu earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      405
    2. 2
      +Edouard
      167
    3. 3
      PsYcHoKiLLa
      131
    4. 4
      Michael Scrip
      73
    5. 5
      Xenon
      72
  • Tell a friend

    Love Neowin? Tell a friend!