9
Jul '10

Do as we say, not as we do

   Posted by: lyle   in Cynicism, Geeky, Stupidity, Work-related

Part of my current work deals heavily with web security, data security and the like. As part of that, I subscribe to a number of information lists, mail services etc.

I signed up to a new one today – one of the better regarded (and indeed recommended by another security auditing agency) ones.

What concerned me during the signup process was this :

You may enter a privacy password below. This provides only mild security, but should prevent others from messing with your subscription. Do not use a valuable password as it will occasionally be emailed back to you in cleartext.

Seriously? Sending – and one assumes storing – a password in clear text is such a bad idea. It’s also a major no-no in every security list – including their own one. D’oh!

Obviously a case of “don’t do what we do, do what we say”.

This entry was posted on Friday, July 9th, 2010 at 15:38 and is filed under Cynicism, Geeky, Stupidity, Work-related. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a reply

Name (*)
Mail (will not be published) (*)
URI
Comment