<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/rss-style.xsl" type="text/xsl"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	    xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	     xmlns:dc="http://purl.org/dc/elements/1.1/"
	   xmlns:atom="http://www.w3.org/2005/Atom"
	     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	  xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>
<channel>
	<title>Thames Water &#8211; Terence Eden’s Blog</title>
	<atom:link href="https://shkspr.mobi/blog/tag/thames-water/feed/" rel="self" type="application/rss+xml" />
	<link>https://shkspr.mobi/blog</link>
	<description>Regular nonsense about tech and its effects 🙃</description>
	<lastBuildDate>Thu, 05 Dec 2019 20:54:51 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://shkspr.mobi/blog/wp-content/uploads/2023/07/cropped-avatar-32x32.jpeg</url>
	<title>Thames Water &#8211; Terence Eden’s Blog</title>
	<link>https://shkspr.mobi/blog</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title><![CDATA[Thames Water don't get password security]]></title>
		<link>https://shkspr.mobi/blog/2019/12/thames-water-dont-get-password-security/</link>
					<comments>https://shkspr.mobi/blog/2019/12/thames-water-dont-get-password-security/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Fri, 06 Dec 2019 07:20:38 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Thames Water]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=33305</guid>

					<description><![CDATA[Thames Water seem to love giving me a new account number each month. That would be fine, but each time they do, I have to manually add that number to my online account.  I&#039;m bored of being their data-entry monkey. So, when they rang today, I told them that I expected them to update my account.  We had the normal back-and-forth and &#34;let me speak to your manager&#34; that accompanies anything deviating …]]></description>
										<content:encoded><![CDATA[<p>Thames Water seem to love giving me a new account number each month. That would be fine, but each time they do, I have to <em>manually</em> add that number to my online account.</p>

<p>I'm bored of being their data-entry monkey. So, when they rang today, I told them that I expected them to update my account.  We had the normal back-and-forth and "let me speak to your manager" that accompanies anything deviating off-script.</p>

<p>A manager called back, we went though account verification, I confirmed I was recording the call, and this is what she said:</p>

<p></p><div style="width: 224px;" class="wp-video"><video class="wp-video-shortcode" id="video-33305-3" width="224" height="224" preload="metadata" controls="controls"><source type="video/mp4" src="https://shkspr.mobi/blog/wp-content/uploads/2019/12/t.mp4?_=3"><a href="https://shkspr.mobi/blog/wp-content/uploads/2019/12/t.mp4">https://shkspr.mobi/blog/wp-content/uploads/2019/12/t.mp4</a></video></div><p></p>

<blockquote><p>We have spoken to our compliance department and if you give us your email address and also your password we can go on and update the new account number for you.</p></blockquote>

<p>I confirmed - they wanted me to read out my whole password. Not just the 4th and 17th character - the whole thing. I - probably a little too rudely - informed them that wasn't happening and, frankly, I didn't believe that either their data protection team nor their IT security team thought it was a good idea.</p>

<p>To be fair, this isn't the fault of the Customer Service agent. She obviously seems reluctant to ask for the password, but has been given some extremely dodgy advice by someone.</p>

<p>So, we came up with a compromise. They would reset my password, log in to my account, fiddle around with it, and then call me with the new password.  And so they did.</p>

<p></p><div style="width: 224px;" class="wp-video"><video class="wp-video-shortcode" id="video-33305-4" width="224" height="224" preload="metadata" controls="controls"><source type="video/mp4" src="https://shkspr.mobi/blog/wp-content/uploads/2019/12/t1.mp4?_=4"><a href="https://shkspr.mobi/blog/wp-content/uploads/2019/12/t1.mp4">https://shkspr.mobi/blog/wp-content/uploads/2019/12/t1.mp4</a></video></div><p></p>

<blockquote><p>Tango hotel alpha mike echo sierra one two three</p></blockquote>

<p>Foolproof!</p>

<p>Let's count the obvious errors....</p>

<ul>
<li>Don't make your customers do work which you could automate.</li>
<li>Don't train your customers to take dangerous risks when it comes to online security.</li>
<li>Don't use easily guessable defaults when resetting passwords.</li>
</ul>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=33305&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2019/12/thames-water-dont-get-password-security/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
	</channel>
</rss>
