gmail security is a joke

William Herrin bill at
Wed May 27 14:28:12 UTC 2015

On Tue, May 26, 2015 at 4:10 PM, Scott Howard <scott at> wrote:
> On Tue, May 26, 2015 at 12:28 PM, Aaron C. de Bruyn <aaron at>
> wrote:
>> If they can e-mail you your existing password (*cough*Netgear*cough*),
>> it means they are storing your credentials in the database
>> un-encrypted.
> No, it doesn't mean that at all.  It means they are storing it unhashed
> which is probably what you mean.

Hi Scott,

It means they're storing it in a form that reduces to plain text
without human intervention. Same difference. Encrypted at rest matters
not, if all the likely attack vectors go after the data in transit.

Bill Herrin

William Herrin ................ herrin at  bill at
Owner, Dirtside Systems ......... Web: <>

More information about the NANOG mailing list