TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Amtrak.com is storing your password in plaintext

18 点作者 maheswaran大约 14 年前
i just forgot my amtrak.com password and tried to reset it, this is what i got<p>Dear &#60;your-name&#62;,<p>Thank you for contacting Amtrak. The login information you requested is listed below. Please save this information for future reference.<p>User ID: &#60;youremailid@yourprovider&#62; Password: &#60;yourp-passwod&#62;<p>If you encounter any login difficulties, contact us online at http://www.amtrak.com/contactus.html or call 1-800-USA-RAIL (1-800-872-7245).<p>Thank you for choosing Amtrak.

4 条评论

latch大约 14 年前
I hate to be pedantic, but just because they send you your password in plain text, doesn't mean they are storing it in plain text.<p>Does it mean they are doing a shitty job? Yes. Is storing a password using two-way encryption more secure than plaintext? Laughably. Still...
评论 #2531429 未加载
bricestacey大约 14 年前
I just tried it and they sent me the same email. They don't necessarily store the password in plaintext as latch has explained.<p>They don't seem to store credit card information for future use, which is a good sign. However, they do store a lot of personally identifiable information that might make sending a password via email illegal in some states (at least Massachusetts [1]).<p>[1] <a href="http://www.mass.gov/Eoca/docs/idtheft/201CMR1700reg.pdf" rel="nofollow">http://www.mass.gov/Eoca/docs/idtheft/201CMR1700reg.pdf</a> - (3)Encryption of all transmitted records and files containing personal information that will travel across public networks, and encryption of all data containing personal information to be transmitted wirelessly.
_ud4a大约 14 年前
was that your actual password you had used or a random password they created and sent you?!
imechura大约 14 年前
I got an email like this from my domain provider the other day. I was curious if someone might be able to sniff the network for SMTP messages then go request a bunch of password resets from the website. There support staff was not too interested in the idea.