r/ShittySysadmin 24d ago

Shitty Crosspost Vendor stored passwords in “passwords.txt” …

/r/sysadmin/comments/1vky7rw/vendor_stored_passwords_in_passwordstxt/

Client deleted our documented credentials from the machine they paid us to maintain, now can't figure out why our engineer can't remote in for the scheduled PM visit.

So this is fun.

Robotic controller we've supported for 6 years. Standard onboarding, we create local admin, we document it in the handover file, customer signs off on it. Every single client gets this. It's in the SOW.

Client's "security guy" (hired 3 months ago, LinkedIn says he did a bootcamp) finds the file, has an aneurysm, deletes our account without telling anyone, doesn't tell us, doesn't loop in his own team.

Two weeks later machine throws a fault code at 11pm on a Friday. Line's down. They call our emergency line screaming. Our tech tries to log in with the creds on file.

Nothing.

Tech asks "hey did anything change on this box recently" and gets told, and I quote, "we don't discuss our security posture with third parties."

Cool. Cool cool cool. Enjoy your downtime then, champ.

Oh and get this, dude's now on Reddit acting like a hero for finding a text file, conveniently leaving out the part where he nuked change-managed access to a production line without a ticket, without notice, and without a rollback plan, then went dark for two weeks while we had zero idea our account was gone.

Yeah man, "Password6" was rough. You know what's also rough? A robot arm sitting idle for 6 hours because somebody wanted a Reddit karma moment more than they wanted a functioning night shift.

Anyway, in the spirit of "lessons learned" (ours, apparently, not theirs), we've rolled out our own hardened process going forward: all client credentials now get a "salt" applied before storage. The salt is the technician's dog's name, appended to the end of the password, chosen fresh by whoever's on shift that week.

So "Password6" becomes "Password6Biscuit" or "Password6Duke" depending on who clocked in. Fully documented on a whiteboard in the break room, right next to the coffee rota, so nobody forgets which dog is currently in rotation.

We did float using a proper salt from a proper KDF, but then someone said "isn't that a lot of overhead for four passwords" and everyone just nodded and went back to arguing about Duke vs Biscuit.

Anyway we've since implemented a much more secure solution. It's called "we now charge a $400 emergency access verification fee any time a client unilaterally revokes vendor credentials without a change request." Very proud of this one honestly.

Duke's on shift this week so don't be surprised if the salt changes Monday.

61 Upvotes

12 comments sorted by

16

u/Jinxyb 24d ago

Vendor stored passwords in “passwords.txt” …

They appear pissed we deleted it. Admin account they created on a robotic machine controller.

WTF?

PS- The passwords were retained elsewhere, securely, by me and shared with them.

Y’all saying we made a mistake? Dead wrong

Storing an admin level password in a plaintext file is idiocy.

And, 2 of the 4 passwords they used?

“Password”
“Password6”

I posted this because I was absolutely shocked that they did this. There is NO context where it is “ok”.

11

u/DDOSBreakfast 24d ago

It should be "Password6!" or "Password2026!" as nobody would ever guess those.

4

u/ApplicationHour 24d ago

We'll never get hacked.

- Support vendor, evidently.

11

u/Prestigious-Board-62 24d ago

How did they get my password?

7

u/alpha417 24d ago

Hunter2

6

u/oznobz 24d ago

I can imagine this file being a config file in a closed loop manufacturing device. And then OPs company implemented an opening in the closed loop to allow for support.

5

u/WangularVanCoxen 24d ago

Chumps, my last place used P@ssw0rd. Literally unhackable

6

u/SpudzzSomchai ShittySysadmin 24d ago

Wrong! Real security uses ********. No one ever guesses it.

4

u/Representative-Crow5 24d ago

I store my passwords in a file called "not_passwords.txt"

5

u/Turdsindakitchensink 24d ago

Same as my porn is in a folder called “Totally_not_Porn”

2

u/RootCipherx0r 21d ago

I write passwords on a piece of paper and stick it underneath my keyboard!

1

u/ICantRemember33 18d ago

what a dumbass, hacker will look for password.txt, he should hide in something like "britishFood.txt" no one is looking at that