Feeds

KCOM-owned Eclipse FAILS to cover up the password 'password'

Serves it in plain text to user via webpage

Beginner's guide to SSL certificates

Exclusive A Register reader has exposed another privacy howler at KCOM - this time involving its Exeter-based ISP Eclipse Internet, which displays passwords in plain text to users via a webpage.

Customers who log in to their personal Eclipse user site are somewhat surprisingly shown the password for their account.

Today's tip of the hat from Vulture Central goes to Steve Foster, who got in touch following our story last week about a KC engineer allegedly revealing a spreadsheet containing unencrypted user IDs and passwords. He told El Reg:

I doubt that you'll be surprised that the utter incompetence within Kingston Communications goes further than Hull. At least as far as Exeter, in fact.

I attach a (redacted) screen grab from Eclipse Internet's management tool.

You'll see that they not only keep their passwords in plain text, they obligingly display them to you in full when you log into their website.

And yes, it does allow 'password'.

Anyone else feeling a tad bit insecure?

We asked KCOM to explain the lax security on display over at Eclipse Internet.

A spokeswoman at the company told The Reg:

Customers can view their password within our secure Eclipse customer portal only after they have logged in using their user name and password to authenticate their details. During the login process the password is not visible in plain text.

Which left your baffled correspondent wondering why the password would need to be displayed, if the same password was used to access the site.

We were also curious to know if there was any progress with the apparent KC spreadsheet blunder that El Reg recently uncovered.

But KCOM's spokeswoman told us there was "no update" on that particular story. ®

Intelligent flash storage arrays

More from The Register

next story
TEEN RAMPAGE: Kids in iPhone 6 'Will it bend' YouTube 'prank'
iPhones bent in Norwich? As if the place wasn't weird enough
Consumers agree to give up first-born child for free Wi-Fi – survey
This Herod network's ace – but crap reception in bullrushes
Crouching tiger, FAST ASLEEP dragon: Smugglers can't shift iPhone 6s
China's grey market reports 'sluggish' sales of Apple mobe
Sea-Me-We 5 construction starts
New sub cable to go live 2016
New EU digi-commish struggles with concepts of net neutrality
Oettinger all about the infrastructure – but not big on substance
EE coughs to BROKEN data usage metrics BLUNDER that short-changes customers
Carrier apologises for 'inflated' measurements cockup
Comcast: Help, help, FCC. Netflix and pals are EXTORTIONISTS
The others guys are being mean so therefore ... monopoly all good, yeah?
Surprise: if you work from home you need the Internet
Buffer-rage sends Aussies out to experience road rage
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.