Here at SmartyHost, we like to keep things casual and have a bit of fun from time to time. But there are some things we don’t joke about – and security is something we take particularly seriously.
Our Platinum upgrade has lots of upfront benefits such as better SPAM protection and centralised control panels. But it’s what you don’t see that’s also exciting – Platinum also has improved security features, including stronger password protection. As a result, we’ve made some changes to the way we manage passwords.
If you’ve already received your Platinum upgrade, you might have noticed that passwords are displayed differently in your Toolkit. You can now see some of your passwords in plain text (rather than concealed by dots or asterisks).
This was a deliberate change by the SmartyHost team, to make it as easy as possible for you to manage your various passwords. Your security isn’t compromised, because you need a password to log in to the Toolkit in the first place, and once you’ve logged in, the page you see is encrypted in transit (sounds a bit Mission Impossible, doesn’t it!).
In plain English, that means it’s a secure page and you can only see your password details once you’ve logged in using your master password.
And of course, we don’t recommend you share that password with anyone unauthorised.
Making life easier, without compromising security
From time to time, you might need to know your ftp or database password to log in and make changes/add things to your website.
However, many of our clients don’t log in regularly enough to remember their passwords off by heart, so concealing them with asterisks can make life difficult.
You might think: ‘no worries, I’ll just reset my password to a new one if I forget’. Unfortunately, giving you the ability to change your passwords via this page presents some complex problems.
Changing your ftp password is no problem – in fact, we encourage you to change it regularly to reduce the likelihood unauthorised access to your account.
However, resetting your database password will likely have a knock-on effect in the backend of your live site, and you can inadvertently bring your whole website down. It’s better to display your password so there’s no need to reset it.
If you really want to reset your database passwords, we recommend you call us first on 1300 721 465.
Protecting your passwords
Your Toolkit is the ONLY place where you can see your passwords in clear (plain) text. At SmartyHost’s end, your passwords are encrypted using lots of different randomly generated 256-bit encryption keys (how many? Can’t tell you, for security reasons
).
We also store your encrypted passwords in a completely separate system so that in the unlikely event that our main system was compromised, the passwords would not be revealed.
Getting technical
We’ve tried to keep this post simple enough for regular mortals (me included!). But we understand that lots of our clients do have advanced technical expertise, and that this might sound lightweight for you. So for those who’d like us to back this up with more technical details, please feel free to call us to discuss further – obviously we’d prefer to keep the specifics unpublished, again for security reasons.
Paul Hassing 12:37 pm on November 25, 2009 Permalink
Dear Megan & Team. Hearty congrats on this blog. It looks mighty fine. And it’s really good to read more of your beaut writing than the odd comment box grab. I wish you every success. Best regards, Paul.