Passwords: Difference between revisions

Back up to the Configuring Category
From AAISP Support Site
m (Correct described above to described below)
Line 98: Line 98:
*Staff cannot see the password you have picked, it is hashed internally.
*Staff cannot see the password you have picked, it is hashed internally.
*Staff can set a different password for you, although we'd suggest that customers set this themselves.
*Staff can set a different password for you, although we'd suggest that customers set this themselves.
*When a Mailbox is deleted passwords hashes are removed within 24 hours.


===Changing Password===
===Changing Password===

Revision as of 14:32, 23 January 2017

This page describes the various account logins and passwords that apply to our various systems. Different systems have different levels of password security depending on the requirements.

When changing passwords always be sure to use a secure password! Most of our systems have a 'Generate Password' button which you can use if you wish. The Information Pack contains some of your account details.

Control Pages (Clueless)

About

The DSL login is used to access the Control Pages as well as what you use in your DSL router to log in to the Internet. This uses the xxx@a or xxx@a.1 style username.

Our control pages are used to manage services and access technical information. They are also the means to set, and where appropriate, to view other passwords as detailed below.

As with the accounts password, the associated email is crucial and someone with access to the email could use a password change request to change the password and access the control pages. This then gives access to all of the other control pages passwords.

Notes:

  • Staff cannot see the password you have picked, it is hashed internally.
  • Staff cannot set a password for you, you have to use the password change process (described below).
  • Staff are able to invalidate your password if you request, and you should advise staff if you think the password is compromised.

Changing Password

A new password can be requested via: https://clueless.aa.net.uk/newpass.cgi

  • Enter in your email and login (Staff can send you a reset email manually if you ask them)
  • Check your email for an email from us
  • Click the link in the email
  • Review the instruction on that page, and then click the 'Set Password' once you're happy with the new password
  • Log on to the Control Pages with your new password


Accounts System Passwords

About

The accounts system login and password are used to allow access to the accounts, statements, and invoices. This is a very important password as we trust that any orders placed with the correct account number and password are genuinely from you or your organisation, and more importantly, from someone that is authorised to spend money with us. This password can be used to order services as well as changing or ceasing existing services.

The email address associated with the account is crucial. Someone with the ability to read emails sent to that email address could read password reset emails and change passwords and then place orders. You need to ensure that you use an email address that you trust to be secure.

The Accounts System is where you can view your invoices, set up Direct Debits etc. You can log in via: http://aa.net.uk/login-priceless.html

The username is your Account Reference - typically AnnnnA, where nnnn are numbers.

Notes

  • Staff cannot see the password you have picked, it is hashed internally.
  • Staff cannot set a password for you, you have to use the password change process (described below).
  • Staff are able to invalidate your password if you request, and you should advise staff if you think the password is compromised.

Changing Password

The password change process is used to set a password, and can be used if you have forgotten your password or simply want to change it. You can use the forgotten password link to request the password change email, or you can ask a member of staff to send it to you.

  1. The password change email is sent to the email address we have for the login. It contains a web link.
  2. The link can only be used on the day of issue, and only until the password is changed or invalidated.
  3. The link is to a secure web site, so that any passwords shown or entered are not visible in the Internet.
  4. Clicking on the link shows the proposed password clearly on the screen, so ensure you are not overlooked.
  5. If the proposed password is not one you can remember, or on rare occasions is inappropriate or rude, you can select pick another
  6. When you are happy, select Set password to set the password. It is displayed, and you can then login if you wish.
    • We strongly recommend using the passwords we suggest as they are random and avoid any association with you or the account. You can, if you wish, enter your own password. If you want to do this, please ask staff and they will show you how. However, entering a password can lead to poor passwords, and password re-use which are not a good idea.
  7. You will then get a second email confirming that the password has been changed. (The password is not included in the email)

Line password

The line password is related to a broadband line, or data SIM or L2TP Internet access. It is considered very low priority as such systems are rarely used as an attack. When using broadband lines or data SIMs, we normally see a verified circuit ID and as such we will allow a correct login with an incorrect passwords if the circuit matches. The password is also included in the information pack and printed on router information cards to make it easy to configure network equipment - which is especially important when you have no Internet connection.

The username used for a line is in the form of xx@a.n where n is the line number, typically 1 where there is just a single line. eg: abc@a.1

Notes:

  • The password can be viewed on the control pages.
  • The password is printed and included on information packs and router information cards.
  • The password can be set as you wish, but a generate password button is provided for convenience.

Changing Password

  1. Log in to the control pages with your Control Page credentials
  2. Click on the line you want to change the password of
  3. Enter a new password, us use the 'Generate Password' to create a new one.
  4. Click OK
  5. Change the password on your router/equipment to use the new one

Email Passwords

About

The username for email is your full email address.

Whilst the email password, used for POP3, IMAP, and authenticated SMTP, may seem relatively low importance, it is not. Email systems are the underpinning of most security as explained above. Unauthorised access to email can allow people to change and access a range or other system's passwords. As such the email passwords have some security.

Notes

  • Staff cannot see the password you have picked, it is hashed internally.
  • Staff can set a different password for you, although we'd suggest that customers set this themselves.
  • When a Mailbox is deleted passwords hashes are removed within 24 hours.

Changing Password

You can set an email password on the control pages, but we recommend using the generate password link to pick one randomly when you do this, for added security.

You can record a reminder for the password if you wish. You should consider security and try to ensure this is not too obvious!

  1. Log in to the Control Pages with your current email address and password, then click on the Change Password link.
  2. Log in to the Control Pages with your main xxx@a login - this will give you access to all your AAISP services, and you'll have access to change Mailbox passwords too.

More on information on the Change Email Password page.

SIP/VoIP Passwords

About

In order to register a VoIP phone against our servers you'll need a password.

VoIP passwords are considered to be slightly higher security because they can be used with equipment to make chargeable calls. However, the main attack for VoIP passwords is to compromise terminal equipment and either use it directly or access the password and login details it is using. Unfortunately the underling protocol prohibits hashing this password internally. However it is usual for only one device to be configed with each VoIP login, and so reasonable that the password is settable but not visible. We also have in place a number of precautions and warning systems to track if VoIP passwords have been compromised.

Notes:

  • The password can be viewed on the control pages, but it is not hashed in our internal systems.
  • The password can be set as you wish, but a generate password button is provided for convenience.

Changing Password

Log in to the Control Pages with your main xxx@a login, you'll see the list of numbers, click on the one in question, click on the Incoming tab, and set the password there.

Read more about VoIP Security

Web Page Hosting

About

If we host your web pages, then you use FTP or rsync to transfer files to our servers. Web pages are not often targeted on our systems but can be a target for attack to display political or other messages. As such we consider this to be a slightly higher security.

The username is the full domain, e.g. www.example.com

Notes:

  • At present, passwords are part of our DNS control pages and so can be viewed and changed and are not hashed.
  • We are working on ways to hash this password, but as some users make use of rsync for web pages, this is providing more complex. We may provide means to have separate ftp (hashed) and rsync (non hashed) passwords in due course.

Changing Password

Log in to the Control Pages with your main xxx@a login, click on the Domain in question, and edit the 'DNS Record' called Password.

Supplied Router WiFi Password

About

If you have a router supplied by AAISP then the WiFi password will be printed on the card on the base of the router and can also be found in the Information Pack.

The router WiFi password is considered relatively low priority. It is possible for someone to attempt to hack your WiFi, so we do suggest a good password, and the system will try to generate a reasonably memorable password with additional digits to provide extra entropy.

Notes:

  • The password can be viewed on the control pages.
  • The password is printed and included on information packs and router information cards.
  • The password can be set as you wish, but a generate password button is provided for convenience.

Changing Password

There are 2 ways of changing the password:

  1. Log in the router and change the password
  2. Log in the Control Pages with your main xxx@a, click on the Line in question, click the Router Settings page, change the WiFi password and then click 'Send Configuration' - This will overwrite any changes you may have made since the router was originally configured by AAISP.

More information on the Router Settings Page

Supplied Router Admin Password

About

The router admin password is considered relatively low priority. It is rare for any directed router attack using a password. The password is included in the information pack and printed on router information cards to make it easy to access the router even when no Internet connection.

Notes

  • The password can be viewed on the control pages.
  • The password is printed and included on information packs and router information cards.
  • The password can be set as you wish, but a generate password button is provided for convenience.