View Single Post
  #121  
Old 02-23-2006, 11:43 PM
TimM TimM is offline
Senior Member
 
Join Date: Jan 2004
Location: The Gym
Posts: 4,564
Default Re: Money Missing From Poker Accounts

[ QUOTE ]
I know for a fact that many online sportsbooks not only do not encrypt your password in their databases, but they actually make it available in plaintext to support personnel. How do I know?

They asked me for it when I called!

It is part of their "security measures" to verify your identity. I was pretty shocked the first time a sportsbook did this.

[/ QUOTE ]

This does not prove they store your password in plaintext. The right way to store passwords is with one-way encryption. You provide the password over the phone, and they have a piece of software that performs the one-way encryption, and compares the result to your encrypted password in the database to see if they match.

Note that any site which can send you a forgotten password via e-mail does not do this. Sites that reset your password to something random, and then e-mail that to you, are more likely to be doing it right.
Reply With Quote