trenitalia.com
Italian Railway
Password change. You’d expect that “use letters and numbers” means “you need to use both letters and numbers”. No, it means “use letters and number *only*”
Password recovery. Asks for e-mail only. No other data.
Password recovery email. Yeah, it contains my plaintext password. AND IT HAS CONVERTED IT TO UPPERCASE. That means it’s even weaker :(
Oh, and we’re talking about the state-owned railroad operator.

trenitalia.com

Italian Railway

  1. Password change. You’d expect that “use letters and numbers” means “you need to use both letters and numbers”. No, it means “use letters and number *only*”
  2. Password recovery. Asks for e-mail only. No other data.
  3. Password recovery email. Yeah, it contains my plaintext password. AND IT HAS CONVERTED IT TO UPPERCASE. That means it’s even weaker :(

Oh, and we’re talking about the state-owned railroad operator.

Short URL for this post: http://tmblr.co/ZwRzdxSUxSsa
blog comments powered by Disqus