# Passwords broken how?

**URL:** <https://boards.straightdope.com/t/passwords-broken-how/75885>\
**Category:** About This Message Board\
**Created:** [August 12, 2001, 5:55am UTC](https://boards.straightdope.com/t/passwords-broken-how/75885 "2001-08-12T05:55:37Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Avumede](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/avumede/32/7235_2.png) [@Avumede](https://boards.straightdope.com/u/Avumede)\
**Post date:** [August 12, 2001, 5:55am UTC](https://boards.straightdope.com/t/passwords-broken-how/75885/1 "2001-08-12T05:55:37Z")

</div>

Are passwords stored in plaintext here? I’m just wondering how paranoid I need to be about the break-in. If the passwords are stored in plaintext, it might be good to change it everywhere I use it. If the password is stored encrypted (what I would expect), then probably (I’m hoping) my password wouldn’t get cracked - and I can rest a little easier.

Can someone let me know please?

---

<div class="post-metadata">

**Author:** ![waterj2](https://avatars.discourse-cdn.com/v4/letter/w/858c86/32.png) [@waterj2](https://boards.straightdope.com/u/waterj2)\
**Post date:** [August 12, 2001, 6:48am UTC](https://boards.straightdope.com/t/passwords-broken-how/75885/2 "2001-08-12T06:48:11Z")

</div>

The person who cracked the boards got administrator access. The administrators have the ability to see what anyone’s passwords are. While they may be stored encrypted, the admins can look at them in plaintext, and presumably so could the cracker.

---

<div class="post-metadata">

**Author:** ![Una\_Persson](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/una_persson/32/346_2.png) [@Una\_Persson](https://boards.straightdope.com/u/Una_Persson)\
**Post date:** [August 12, 2001, 1:23pm UTC](https://boards.straightdope.com/t/passwords-broken-how/75885/3 "2001-08-12T13:23:30Z")

</div>

That’s not entirely true. Under vBulletin, the Admins cannot see the password from the control panel, in plaintext or otherwise. But there are two other ways to get the plaintext password, if one if really tricky…it’s what I have to do on my Board, since e-mailing passwords does not work on the UnaBoard.

---

<div class="post-metadata">

**Author:** ![Ringo](https://avatars.discourse-cdn.com/v4/letter/r/779978/32.png) [@Ringo](https://boards.straightdope.com/u/Ringo)\
**Post date:** [August 12, 2001, 3:43pm UTC](https://boards.straightdope.com/t/passwords-broken-how/75885/4 "2001-08-12T15:43:10Z")

</div>

The OP brings to mind a related thought, that being that it’s generally not a good idea to use the same password at multiple sites.

---

<div class="post-metadata">

**Author:** ![daffodil](https://avatars.discourse-cdn.com/v4/letter/d/d6d6ee/32.png) [@daffodil](https://boards.straightdope.com/u/daffodil)\
**Post date:** [August 12, 2001, 6:01pm UTC](https://boards.straightdope.com/t/passwords-broken-how/75885/5 "2001-08-12T18:01:50Z")

</div>

What _if_ someone used my password and good name _lol_ ?

Whatever can they post that would make me upset?

---

<div class="post-metadata">

**Author:** ![Avumede](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/avumede/32/7235_2.png) [@Avumede](https://boards.straightdope.com/u/Avumede)\
**Post date:** [August 12, 2001, 9:45pm UTC](https://boards.straightdope.com/t/passwords-broken-how/75885/6 "2001-08-12T21:45:18Z")

</div>

> [@](#):
>
> \*Originally posted by beatle \*  
> The OP brings to mind a related thought, that being that it’s generally not a good idea to use the same password at multiple sites.

Yes, of course. I know that. But for god’s sakes, I have at least 20 sites I need passwords for. Remembering a unique stong password for each site is impossible. Reuse is simply the only sane option.

---

<div class="post-metadata">

**Author:** ![waterj2](https://avatars.discourse-cdn.com/v4/letter/w/858c86/32.png) [@waterj2](https://boards.straightdope.com/u/waterj2)\
**Post date:** [August 12, 2001, 10:10pm UTC](https://boards.straightdope.com/t/passwords-broken-how/75885/7 "2001-08-12T22:10:22Z")

</div>

I have one password that I use for places where security is not much of a concern. If someone found it, they’d be able to read the online NY Times pretending to be me, and stuff like that. Aside from that one, and using the same password for two different remote servers at my college, I manage the rest by memorizing them all. Of course, there’s really very little anyone could do with access to my email, except read some spam that they didn’t recieve.

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [August 12, 2001, 11:23pm UTC](https://boards.straightdope.com/t/passwords-broken-how/75885/8 "2001-08-12T23:23:47Z")

</div>

> [@](#):
>
> \*Originally posted by waterj2 \*  
> While they may be stored encrypted, the admins can look at them in plaintext, and presumably so could the cracker.

They’re not encrypted; they’re stored in plaintext in the database. However, the vBulletin administration software doesn’t show the passwords by default. If you get the _database_ password, on the other hand, then you can see them all.
