Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




95 posts

Master Geek
+1 received by user: 9


Topic # 223624 9-Oct-2017 11:51
Send private message

Something I've been meaning to ask for a while.

 

We all have a login and password for our broadband connection. Now I thought that password would be fully encrypted and invisible to the ISP team, but it seems it is not. They can see the password and will even ask for the password as confirmation of who I am.

 

Is this normal? Not particularly happy with it, but in all other aspects the ISP is great.


Create new topic
21373 posts

Uber Geek
+1 received by user: 1257

Trusted
Lifetime subscriber

  Reply # 1879818 9-Oct-2017 11:55
6 people support this post
Send private message

Most ISP are port based authentication anyway so does not matter what username and password are

Linux




Ex JohnR VodafoneNZ 17 years 4 days

3273 posts

Uber Geek
+1 received by user: 1057

Subscriber

  Reply # 1879859 9-Oct-2017 12:59
3 people support this post
Send private message

Majority are doing port based authentication for PPP and just falling back to user/pass if that doesn't work for some reason.

 

We still allocate a username/pass, the password gets stored in an encrytped database but can be "unhidden" if required by a support tech. The password doesn't get used for anything else though so really just don't see the issue. I would only start to worry if the PPP password was the same one used for getting in to billing portals and things where credit cards are stored (but then again, the CC number shouldn't be stored in plain text anyway so maybe another moot point?)


 
 
 
 


I fix stuff!
1590 posts

Uber Geek
+1 received by user: 266

Trusted
Vocus
Subscriber

  Reply # 1879860 9-Oct-2017 13:00
One person supports this post
Send private message

Also depends on the ISP, don't tar them all with the same brush


'That VDSL Cat'
7131 posts

Uber Geek
+1 received by user: 1402

Trusted
Spark
Subscriber

  Reply # 1879867 9-Oct-2017 13:06
Send private message

Spark don't hold customers passwords.

 

for email, the customer set the password through their selfservice tools.

 

 

 

For Internet, Port based auth is used. As such the BGN will accept any password and/or username as long as it is not blank and does not have any strange Unicode characters.

 

 





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have.




95 posts

Master Geek
+1 received by user: 9


  Reply # 1879870 9-Oct-2017 13:11
Send private message

Thanks Linux - I had to look that one up :-)

 

@Chevrolux alludes to the issue that seemed to be of concern to me.

 

There are few things here.

 

1. Modem connection. I've always been BYO modems so don't know if that makes a difference as I assume any modem supplied by the ISP would have the line details included. Mine have always connected as per the ISP instructions using a username and pw - I've been with the same ISP for over 6 years.

 

2. Web account login. This uses the same login details as the modem, so with those details anyone can login and see name, address, phone numbers, payment details etc. Now, I assume it would be normal practice for the ISP staff would be able see these details, but these would be secure details (hopefully) on their servers. I am surprised they have access to the password as well. It is that aspect that I'm wondering if it is standard practice or if my ISP is an exception.

 

3. Can't think of any reason that staff should be able to access a password. It is an easy get out of jail card if people forget their pw, but not really acceptable these days IMHO. Nice to see that at least Spark (thanks @hio77) seem to agree on that one.


'That VDSL Cat'
7131 posts

Uber Geek
+1 received by user: 1402

Trusted
Spark
Subscriber

  Reply # 1879874 9-Oct-2017 13:22
Send private message

MartinGZ:

 

 

 

2. Web account login. This uses the same login details as the modem, so with those details anyone can login and see name, address, phone numbers, payment details etc. Now, I assume it would be normal practice for the ISP staff would be able see these details, but these would be secure details (hopefully) on their servers. I am surprised they have access to the password as well. It is that aspect that I'm wondering if it is standard practice or if my ISP is an exception.

 

 

Missed commenting on this one.

 

 

 

MySpark passwords are not held iver, once again self service completely for customers to manage their passwords.

 

 

 

The idea of using authentication based identification these days is just an unneeded overhead.

 

There are also many abusable flaws to this that used to get hit back in the day on those who previously did authentication (since moved to port)

 

 

 

Port auth isn't foolproof, chorus can do maintenances and leave the customer's connection in limbo on a new port till records are updated on both sides although 95% of the time RSP's have a "special" profile in this case that still allows service, sometimes at a lower limit.

 

most RPS's have teams that manage these sorts of things or go as far as to have it completely self provisioned (automation)





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have.


13540 posts

Uber Geek
+1 received by user: 1648


  Reply # 1879938 9-Oct-2017 14:48
One person supports this post
Send private message

Considering how many people use the same password for multiple things (which people shouldn't do, but it happens), that is a concern. Especially with all the systems that get hacked these days. Another big hack today see in NZ.


2269 posts

Uber Geek
+1 received by user: 679

Trusted

  Reply # 1879995 9-Oct-2017 17:35
Send private message

hio77:

 

Spark don't hold customers passwords.

 

for email, the customer set the password through their selfservice tools.

 

For Internet, Port based auth is used. As such the BNG will accept any password and/or username as long as it is not blank and does not have any strange Unicode characters.

 

 

The only reason why the username is used in Spark is for debugging purposes such as if you are mis-provisioned by Chorus or another LFC then the agent can ask you to change the username to "findmeplease" and then they can search in the authentication logs and find you.

 

And the username can be upper,lowers, numbers, @ and "." and pretty much anything else will cause the request to be rejected.






'That VDSL Cat'
7131 posts

Uber Geek
+1 received by user: 1402

Trusted
Spark
Subscriber

  Reply # 1879996 9-Oct-2017 17:40
Send private message

BarTender:

 

 

 

The only reason why the username is used in Spark is for debugging purposes such as if you are mis-provisioned by Chorus or another LFC then the agent can ask you to change the username to "findmeplease" and then they can search in the authentication logs and find you.

 

And the username can be upper,lowers, numbers, @ and "." and pretty much anything else will cause the request to be rejected.

 

 

Yep exactly.

 

 

 

Was refering to those who somehow manage to Copy and paste extra junk in...

 

Such as &#8206;user@spark.co.nz

 

 

 

That's rejected, pretty reasonably however the character is actually relatively invisible.  





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have.


UHD

554 posts

Ultimate Geek
+1 received by user: 235


  Reply # 1880030 9-Oct-2017 19:08
2 people support this post
Send private message

chevrolux:

 

Majority are doing port based authentication for PPP and just falling back to user/pass if that doesn't work for some reason.

 

We still allocate a username/pass, the password gets stored in an encrytped database but can be "unhidden" if required by a support tech. The password doesn't get used for anything else though so really just don't see the issue. I would only start to worry if the PPP password was the same one used for getting in to billing portals and things where credit cards are stored (but then again, the CC number shouldn't be stored in plain text anyway so maybe another moot point?)

 

 

 

 

Systems engineers trying to come up with a satisfactory way to explain this.

 

 

 


Create new topic



Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

Fujifilm X beats its best with new top of the range, high-performance camera
Posted 24-Feb-2018 14:05


One million kiwis affected by cybercrime
Posted 24-Feb-2018 13:58


New Zealanders want to engage with government online and via mobile apps
Posted 24-Feb-2018 13:56


Samsung launches Samsung Max
Posted 24-Feb-2018 13:52


CPTPP text and National Interest Analysis released for public scrutiny
Posted 21-Feb-2018 19:43


Foodstuffs to trial digitised shopping trolleys
Posted 21-Feb-2018 18:27


2018: The year of zero-login, smart cars & the biometrics of things
Posted 21-Feb-2018 18:25


Intel reimagines data centre storage with new 3D NAND SSDs
Posted 16-Feb-2018 15:21


Ground-breaking business programme begins in Hamilton
Posted 16-Feb-2018 10:18


Government to continue search for first Chief Technology Officer
Posted 12-Feb-2018 20:30


Time to take Appleā€™s iPad Pro seriously
Posted 12-Feb-2018 16:54


New Fujifilm X-A5 brings selfie features to mirrorless camera
Posted 9-Feb-2018 09:12


D-Link ANZ expands connected smart home with new HD Wi-Fi cameras
Posted 9-Feb-2018 09:01


Dragon Professional for Mac V6: Near perfect dictation
Posted 9-Feb-2018 08:26


OPPO announces R11s with claims to be the picture perfect smartphone
Posted 2-Feb-2018 13:28



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.