We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

TalkTalk security flaws or am I being fussy?

power2consumers
power2consumers Posts: 36 Forumite
edited 13 February 2011 at 9:28PM in Broadband & internet access
I wanted to change my email password, could not do so cos was not registered to my accout, so called customer service to ask them what was wrong. She asked for my name, address and DOB, hardly the most confidential of information, then proceeded to ask me what address I told her and she said so thats the one with the password sax?x? and told me my whole password. Now it might be just me and maybe I am overreacting but
1) Look how easy it was for her to hand out my password, the only information I gave was my name, address and DOB, and that was enough for her to tell me my entire password. Those 3 things are hardly the most classified of information about someone, I mean family, friends, neighbours, anyone who steals ur mail etc can have that information.
2) Should employees actually be able to see your email passwords, I mean think about how we might get frustrated with talktalk and might get a bit blunt or rude to customer service staff and at the end of the day its a fact employees do things to get back at customers eg spit in the Burger of a rude customer, or some employees are just natural !!!!!!!s, aka maldives wedding fiasco.
When I tried to explain she tried to say "but we did our checks" and she could not comprehend that those 3 things were not checks and information anyone could have and people for 100s of reasons could want it I.e suspicious GF could want to access emails or other things,
Does my point make sense, or is it an overreaction?

Comments

  • kwikbreaks
    kwikbreaks Posts: 9,187 Forumite
    I don't think you are being fussy.

    For them to be able to quote your pasword it must be stored somewhere in plain text and that should never be done. They should be storing an md5 of your password, creating an md5 of what you type in and comparing those. The only disadvantage is that if you forget your password all that can be done is to reset it, notify you what the new password is and require you to change it within a short timescale. Email is not encrypted so sending your new password in plain text isn't secure which is why it should be time limited and you required to change it.

    None of that is radical it's the bare minimum that should be done - it could even be a data protection act requirement but probably isn't.
  • jayme1
    jayme1 Posts: 2,154 Forumite
    Part of the Furniture Combo Breaker
    I would ditch the ISP email and just use something like hotmail or gmail, they would be much more secure and if you ever left talktalk you wouldnt loose your email address.
  • TalkTalk
    TalkTalk Posts: 1,948 Organisation Representative
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    Hi power2consumers,

    I appreciate where your coming from however these "Security checks" do adhere to DPA regulations and although i appreciate you don't feel they are sufficient it is an approved process.

    With regards to the email account, almost all accounts have now been migrated into our new myaccount portal which means that we "staff" don't actually have any visibility of your email account password.

    We do have some email accounts that are yet to migrate which i suspect yours is one of them however once fully migrated it is the customer and only the customer who will see the password.

    Also the advice from JANME1 should be considered, using something like yahoo or gmail may be for the best, regardless of what ISP you have you can always keep them unlike your talktalk email which will be deleted when/if you leave talktalk.


    Regards
    Stephen
    Official Company Representative
    I am the official company representative of Talk Talk. MSE has given permission for me to post in response to queries about the company, so that I can help solve issues. You can see my name on the companies with permission to post list. I am not allowed to tout for business at all. If you believe I am please report it to forumteam@moneysavingexpert.com This does NOT imply any form of approval of my company or its products by MSE"
  • stubbyd
    stubbyd Posts: 64 Forumite
    Part of the Furniture 10 Posts Combo Breaker
    Does my point make sense, or is it an overreaction?

    Your point makes perfect sense and isn't an over-reaction.

    This practice was commonplace amongst ISPs a few years back and I guess they all utilised similar backend systems for managing accounts .... but as noted by the TalkTalk rep above they along with most others have migrated from older systems that did this.

    IMO, they should have done this years ago but still ...

    The other grievance I have regards passwords is websites that want you to be secure but then don't allow punctuation as part of the password - or restrict the length to 8 characters ... grrr!
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.7K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.7K Work, Benefits & Business
  • 600.1K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.