[security flaw] Ubuntu is a plain text offender

Jordon Bedwell jordon at envygeeks.com
Tue May 24 18:51:29 UTC 2011


On 5/24/2011 1:45 PM, Chuck Peters wrote:
> Insecure?  If you are that concerned about plain text passwords being
> emailed to you I suggest you run your own mail server and require the smtp
> transactions use TLS.  I think the Canonical and Ubuntu people that
> administrate the mail servers make reasonable choices for keeping the
> information secure. I would be very surprised if they run mailman on a server
> with untrusted users having access to unencrypted passwords.

Because all people run their own mail servers right?

> Personally I am more concerned about sites like plaintextoffenders.com that
> use quantserve.com to track us.  A site attempting to educate people about
> passwords should not be sharing who visits the site with anyone in my
> opinion.

Better close your bank accounts too then.

> Recently I helped someone with installing and updating TurboTax and the
> during the update I checked on what the update was, which led to a link at
> intuit with tracking from facebook included.  A serious breach of trust for
> something like tax software!

I'm sorry, did they happen to transmit your tax information with that?




More information about the ubuntu-users mailing list