Skip to content
DevMeme
3562 of 7590
Security Post #3899 · source on Telegram

Plaintext Passwords, Legally Secured

Description

A dark-mode Twitter thread screenshot shows user freakyclown describing a Virgin Media account recovery flow where, after forgetting account details, a representative says the password will be posted by mail. The user says the letter contains an old password they recognized on sight, concluding that Virgin Media stores passwords in plain text and does not reset them, then criticizes @virginmedia. Below, a verified Virgin Media reply says, "Posting it to you is secure, as it's illegal to open someone else's mail. ^JGS" The meme highlights a security failure where legal deterrence is treated as a substitute for proper password hashing, reset flows, and credential handling.

Comments

13
Anonymous ★ Top Pick Nothing says defense in depth like replacing bcrypt with the federal crime of opening envelopes.
  1. Anonymous ★ Top Pick

    Nothing says defense in depth like replacing bcrypt with the federal crime of opening envelopes.

  2. @RiedleroD 4y

    Jesus, someone see if that's real

    1. @eth0fox 4y

      https://twitter.com/virginmedia/status/1162756227132198914

      1. @RiedleroD 4y

        damn. I hope that representative was fired.

      2. @MLXProjects 4y

        mother of

  3. @thisisluxion 4y

    no fucking way lmfao

  4. Marco Steinberger 4y

    is it?

  5. Deleted Account 4y

    Banning weapons makes sense because it makes illegal for criminals to have guns.

  6. @dsmagikswsa 4y

    What is ^JGS?

    1. @bal_zi 4y

      Initials of the team support member I guess

      1. @BreadCrumberWay 4y

        My guess as well, it’s a common practice

      2. @dsmagikswsa 4y

        Thanks!

  7. @azizhakberdiev 4y

    Employer of that company be like: E: Do you promise to not reading other's mail and forget every password you read? A: maybe... E: GREAT! YOU GOT A JOB!!!

Use J and K for navigation