The Daily WTF: Curious Perversions in Information Technology
Welcome to TDWTF Forums Sign in | Join | Help
in Search

Secure Payslips

Last post 02-06-2010 2:15 AM by nat42. 9 replies.
Page 1 of 1 (10 items)
Sort Posts: Previous Next
  • 01-31-2010 8:54 PM

    Secure Payslips

    The (supposed) industry leading, multi-national engineering compary I work for has just implemented a new payslip system. They email a password protected pdf copy of your payslip every month.

    Sounds fine so far, right? The wtf is that they also send a second plain text email, at the same time as the payslip, that contains your password. Every month.

    I'm *almost* surprised by this. Although, given that the industry-leading, fantastic, brilliant application that runs the core business is based on VB6 may say something.

  • 01-31-2010 11:42 PM In reply to

    Re: Secure Payslips

    I seem to recall PDF passwords not being very secure, too...

  • 02-01-2010 9:01 AM In reply to

    • Mole
    • Top 100 Contributor
    • Joined on 09-23-2008
    • Posts 293

    Re: Secure Payslips

     Kinda like the websites that asterix out your password as you setup your account, and then email it to you to ensure you don't forget it?

  • 02-01-2010 12:36 PM In reply to

    Re: Secure Payslips

    Mole:

     Kinda like the websites that asterix out your password as you setup your account, and then email it to you to ensure you don't forget it?

    Because nobody cracks email accounts.


    I contribute to the F@H Project because I hated seeing my grandfather die from the implications of Alzhiemers
    Filed under:
  • 02-01-2010 1:26 PM In reply to

    Re: Secure Payslips

    Indrora:

    Mole:

     Kinda like the websites that asterix out your password as you setup your account, and then email it to you to ensure you don't forget it?

    Because nobody cracks email accounts.

    Of course not.  Email accounts have asterisks, too.
  • 02-01-2010 1:33 PM In reply to

    Re: Secure Payslips

     

    Indrora:

    Mole:

     Kinda like the websites that asterix out your password as you setup your account, and then email it to you to ensure you don't forget it?

    Because nobody cracks email accounts.

    Or use some kind of network sniffer/ man-in-the-middle-attack to grab a copy of any mail that contains the words password/passwd/username/user etc. People ofter forget that mail is not as secure even as a letter, it's a post card where anyone handling the item can read it. I blame in part the user interfaces, for showing images of letters instead of postcards.
    The Adventurous Space Janitor
  • 02-01-2010 1:56 PM In reply to

    Re: Secure Payslips

    metallurg:
    The wtf is that they also send a second plain text email, at the same time as the payslip, that contains your password. Every month.
    I had a similar experience once with a salary review when I was working in a different country to my manager. He wanted to send me details of the review via email. I was pissed off with him (and about to quit anyway) so played the "email is not really secure" card to see what hoops I could get him to jump through. His ultimate response was to send the review in a password protected zip file and send the password in a separate email. For added security the password was not sent in plain text. No - he thought up a code all by himself. The password was encoded as a sentence that read "The password is name of the company backwards". And all of this sent through the companies email servers!
  • 02-01-2010 2:13 PM In reply to

    • Mole
    • Top 100 Contributor
    • Joined on 09-23-2008
    • Posts 293

    Re: Secure Payslips

    OzPeter:
    The password was encoded as a sentence that read "The password is name of the company backwards". And all of this sent through the companies email servers!
    Classy. I like it. I've had emails where the password was the name of the company (all in lower case for ease of use), but never had it backwards. I'll have to forward your message to management. You don't mind if they take the credit and run with it do you? No? Excellent. 

  • 02-01-2010 6:30 PM In reply to

    Re: Secure Payslips

    I should mention that the password for the payslips is really hard to work out - it's the persons surname, followed by their start date.

  • 02-06-2010 2:15 AM In reply to

    • nat42
    • Not Ranked
    • Joined on 05-29-2008
    • Posts 21

    Re: Secure Payslips

    metallurg:

    I should mention that the password for the payslips is really hard to work out - it's the persons surname, followed by their start date.

    Wow; that is insecure. Our payslips are emails with attached zipped PDF files, encrypted with a randow password for strength! [All passwords are allocated by payroll and can not be changed; they consist of two [2] numeric digits. I estimate that with that level of security one would need at least a 1 minute with a 386-based PC to brute force the files; clearly we have the superior system!!]
Page 1 of 1 (10 items)
Powered by Community Server (Non-Commercial Edition), by Telligent Systems