GMBill.com CEO Responds to 'Plaintext Passwords' Tweet

SAN FRANCISCO — A tweet by an adult industry journalist spread like wildfire last week, bringing mild hysteria to message boards.

The tweet made by Violet Blue said: “One of the top adult affiliate credit card processing payout companies is storing passwords in plaintext.”

On Saturday, Blue confided to XBIZ that the top affiliate processor discussed in the tweet was GMBill.com.

“All the passwords are stored in plaintext on the server and in user accounts,” she said.

Blue went on to discuss another concern: “They only do payouts via wire transfer/EFT, and so that means everyone's bank account credentials are 99 percent likely to be stored in plaintext on the server too.”

“One not-terribly-clever hacker could do a lot of damage with tools readily available online,” she emphasized to XBIZ.

Sunday morning, GMBill’s CEO and founder, Garion Hall — also CEO and founder of AbbyWinters.com — responded to Blue’s tweet over visible plaintext passwords.

“[Blue] is incorrect,” Hall told XBIZ. “All passwords are stored encrypted but are decrypted when the user logs in — for example, once a user successfully authenticates and logs in, their password is decrypted.” Hall continued saying that the process “is widely considered an effective security practice.

“GMBill.com acknowledges the practice of showing users their passwords on-screen is falling out of favor — due to the risk of ‘shoulder surfing’ or a malicious user accessing browser cache), but is still common practice,” he said.

Hall noted he could come up with numerous examples over this but pointed to iCloud as one.

“For example, Apple’s Keychain also shows users passwords of sites and networks they have access to, after entering their admin password,” he said. “This is considered low risk, as at most it affects a single user.”  

Hall also addressed Blue’s accusation that affiliate’s EFT, or wire, bank account details are at risk.

“These are the same details every company places on invoices and some websites to customers,” Hall said. “Access is secured through standard security practices; by taint checking of all database inputs, all code being encrypted — including database access credentials — and fine-grained privilege separation for database user accounts.

“However, we have taken these accusations as a reminder that security never sleeps,” he said. “We have added velocity controls to the affiliate login process, blanked previously visible passwords, and even-more-thoroughly encrypted affiliate bank details. These changes will be released to production servers as a priority.”

Hall emphasized to XBIZ that there was no breach at GMBill; he also said he invites concerned parties to direct specific questions to him at garion@gmbill.com.

“GMBill.com conducts regular log scans to identify suspicious activity and has undertaken an especially close look in light of these accusations. We confirm there has been no breach of our security systems, no affiliate, client or customer data has been accessed by unauthorized parties, and all security measures in place continue to function appropriately.”

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

CAM4 Debuts Weekly 'Skyy Knox's CAM Crawl' Livestream

CAM4 is launching "Skyy Knox’s CAM Crawl," a new livestream running every Sunday at 3 p.m. PDT.

Texas Judge Pauses AG Ken Paxton's Aylo Lawsuit Until SCOTUS Decision

A Texas district judge granted a request Wednesday to pause proceedings in the lawsuit filed by Attorney General Ken Paxton against Aylo over its implementation of Texas’ controversial age verification requirements for Pornhub, pending the outcome of the Free Speech Coalition-led lawsuit against Paxton, which will be heard by the Supreme Court during the next term.

Author of UN Report Recommending Worldwide Criminalization of Sex Work, Porn to Speak at NCOSE Summit

Jordanian activist Reem Alsalem, a special rapporteur on violence against women and girls at the United Nations Human Rights Council who recently issued a controversial report recommending that governments abolish all forms of sex work, including porn, will speak at anti-porn lobby NCOSE’s 2024 summit in August.

Spicey AI Voice Chat Platform Launches

Spicey AI, a platform that uses artificial intelligence to create interactive voice messages from chatbots based on adult performers, has launched.

Utherverse to Host 8th Annual VirtualCon in September

Virtual reality and metaverse technology company Utherverse will hold the eighth edition of its annual virtual conference, VirtualCon, from Sept. 26-28.

Pornhub Shuts Down Access in Nebraska Over Age Verification

Aylo began blocking access to Pornhub in Nebraska on Monday, in anticipation of the state’s new age verification law — one of many such bills promoted by religious conservatives around the country — which is scheduled to go into effect Thursday.

FeelMe AI Launches 3 New Subscription Tiers

FeelMe AI has launched three new subscription levels, allowing users to connect compatible Kiiroo sex toys to their videos for interactive solo play.

CamSoda Launches AI Girlfriend Builder

CamSoda has debuted a personalized "AI girlfriend" feature, which allows users to create their very own virtual companion at no charge, including free NSFW role-play and chat.

Free Speech Organization Comes Out in Support of Wisconsin Professor Who Posted on OnlyFans

After a University of Wisconsin-La Crosse faculty tribunal recommended stripping veteran professor of communications Joe Gow of tenure last week due to Gow having unremorsefully created and appeared in adult content, a major free speech organization has come out in his support.

MojoHost Unveils Public Cloud Service MojoCompute

MojoHost has launched MojoCompute, a new cloud service, as the central component of its MojoCloud product offerings.

Show More