{"id":3322,"date":"2017-03-08T16:04:53","date_gmt":"2017-03-08T23:04:53","guid":{"rendered":"https:\/\/www.whitefirdesign.com\/blog\/?p=3322"},"modified":"2017-03-08T16:04:53","modified_gmt":"2017-03-08T23:04:53","slug":"cloudaccess-net-still-storing-non-hashed-ftpsftpssh-passwords","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2017\/03\/08\/cloudaccess-net-still-storing-non-hashed-ftpsftpssh-passwords\/","title":{"rendered":"CloudAccess.net Still Storing Non-Hashed FTP\/SFTP\/SSH Passwords"},"content":{"rendered":"<p>Back in May of 2015 we had put out a post discussing the fact <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2015\/05\/06\/cloudaccess-net-stores-non-hashed-ftpsftpssh-passwords\/\">that the web host CloudAccess.net was storing\u00a0FTP\/SFTP\/SSH passwords in non-hashed form<\/a>. Here is how we explained why storing them in hashed form was\u00a0important, at that time:<\/p>\n<blockquote><p>One of the measures that needs\u00a0to be taken\u00a0is to\u00a0store passwords as securely as possible, which means storing them in hashed form. You can think of a password hashing as one-way encryption. That is, the data is encrypted, but it cannot be decrypted, so the underlying password is not retrievable in normal circumstances.\u00a0With this type of password storage when someone tries to log in the password they input is hashed and then compared with the stored password hash to see if they are the same. With hashed passwords even if someone gets access to the stored passwords it would be difficult for them to do anything with them, since they would first have to crack the hashes.<\/p><\/blockquote>\n<p>Then back in January we received a <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2015\/05\/06\/cloudaccess-net-stores-non-hashed-ftpsftpssh-passwords\/#comment-80511\">comment<\/a> on the post apparently from the <a href=\"https:\/\/www.cloudaccess.net\/about-us\/meet-the-team\/878-jonathan-james-gafill-chief-executive-officer.html\">CEO of CloudAccess.net<\/a>:<\/p>\n<blockquote><p>I represent CloudAccess.net, the company that you are writing about. To clarify, we do not store ANY passwords or sensitive information in clear text. Your assumptions are incorrect here. In the future if you have any questions or concerns you may ask us directly and we will explain further to alleviate your concerns. Thank you.<\/p><\/blockquote>\n<p>We didn&#8217;t really know what to make of that since it didn&#8217;t address the issue of the passwords not being stored in hashed form, instead only claiming that they were not stored in clear text, which isn&#8217;t the only way non-hashed passwords could be stored. So either the person didn&#8217;t really understand the issue at hand or they were trying to divert from the real issue.<\/p>\n<p>Whatever was the case there, the issue hasn&#8217;t been resolved as we were just working on a website hosted with CloudAccess.net and found that they are still storing the FTP\/SFTP\/SSH passwords in non-hashed form. You can see below that on the relevant page in their control panel there is still the option to \u00a0view the password by clicking on &#8220;View hidden password&#8221;, which would not be possible if they were hashed:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3323\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2017\/03\/cloudaccess-net-non-hashed-password.png\" alt=\"\" width=\"890\" height=\"600\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2017\/03\/cloudaccess-net-non-hashed-password.png 890w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2017\/03\/cloudaccess-net-non-hashed-password-300x202.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2017\/03\/cloudaccess-net-non-hashed-password-768x518.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Back in May of 2015 we had put out a post discussing the fact that the web host CloudAccess.net was storing\u00a0FTP\/SFTP\/SSH passwords in non-hashed form. Here is how we explained why storing them in hashed form was\u00a0important, at that time: One of the measures that needs\u00a0to be taken\u00a0is to\u00a0store passwords as securely as possible, which &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2017\/03\/08\/cloudaccess-net-still-storing-non-hashed-ftpsftpssh-passwords\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;CloudAccess.net Still Storing Non-Hashed FTP\/SFTP\/SSH Passwords&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25],"tags":[111],"class_list":["post-3322","post","type-post","status-publish","format-standard","hentry","category-bad-security","tag-cloudaccess-net"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3322","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=3322"}],"version-history":[{"count":3,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3322\/revisions"}],"predecessor-version":[{"id":3326,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3322\/revisions\/3326"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=3322"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=3322"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=3322"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}