PDA

View Full Version : Is it normal for tech. support to ask your email password?


cynix
28-07-2006, 23:26
On the 'phone to broadband tech. support tonight (see other thread about dropouts in renfrewshire) and before they agreed to send out an engineer they apparently had to do a "security test" by asking my ntl email address and password.

Never heard of that happening before and just wondering if that is now normal practice or if I should be going off to change my password ASAP. :)

quadplay
28-07-2006, 23:32
They can see it on screen, so it might be the only available method of authenticating you as the account holder if there are no other security details in the billing system. As long as you called them and not the other way round, I wouldn't worry too much.

MikeyB
29-07-2006, 09:40
They can see it on screen, so it might be the only available method of authenticating you as the account holder if there are no other security details in the billing system. As long as you called them and not the other way round, I wouldn't worry too much.

Are you serious? They can actually see our passwords???
What's the point in having them if they can be seen? Surely thats a huge security risk, particularly if the systems were hacked into somehow.

Any systems we right at work, the passwords cannot be seen, usually stored as a one-way hash of the password, which cannot be reversed back into the password.

Toto
29-07-2006, 10:55
Are you serious? They can actually see our passwords???
What's the point in having them if they can be seen? Surely thats a huge security risk, particularly if the systems were hacked into somehow.

Any systems we right at work, the passwords cannot be seen, usually stored as a one-way hash of the password, which cannot be reversed back into the password.

They need to support a customer, at all levels, so they will have to see an account password to pass that back to the customer, following a strict DPA check of course.

They could reset the password, but to what address can they send it to if the customer can't access email?

Sucks I know, but you have to weight the security of data with the customer experience, and I'm sure we'd have a ton of people moaning here if they forgeot their password, and had to wait for a Royal Mail letter with their password in it because ntl had redesigned their system for greater security

Catch 22 situation.