I recently found out that EC|Council is storing passwords (and possibly other sensitive information) in clear text. Does anybody else have an issue with this or is it just me?
Here is the forum thread discussing the problem:
https://portal.eccouncil.org/forum/forum_posts.asp?TID=1280&PN=1&TPN=3
This is EC|Council's response to the security issue:
Hi,
Because of the flexibility to the users EC-Council provides password to the concerned members though E-mails and the password will be sent to registered E-mail ID's only.
The company keeps user information secure and confidential. The user passwords are stored in very secured way following EC-Council's strict confidentiality rules and regulations.
You can keep all your EC-Council certifications active with the help of Continuing Profession Education provided by EC-Council.
This was my response:
I expect more from a certifying infosec organization. Storing a user's credentials in clear text seems like a really basic security vulnerability. What else is being stored in plain text? My address? Credit card info?
I'm not trying to be hard on you guys, but I do hold you to a higher standard. I understand you keep our information "very secured", but storing original passwords in a database leads me to believe otherwise. I just hope other users don't use their EC|Council portal password on other sites (especially for their email).
One last thing, can you point me to "EC-Council's strict confidentiality rules and regulations"? I would like to see your policies for storing personal information.
Thank you.
- Ryan
Am I overreacting?
- Ryan