¶ ile paragrafa bağlantı verin veya alıntıyı künyesiyle kopyalayın. Üretilen bağlantı kimlikleri resmî paragraf numarası değildir.
CNIL
COMMISSION NATIONALE
INFORMATIQUE & LIBERTÉS
# The President

Examination of the case :
Paris, on 13 JUIN 2019
Our Ref.: MLD/JLI/XD/SGE/DAU/CM191944
Case no. 19001065
(to be referenced in all correspondence)
Sir,
This is further to the exchanges that took place between my services and yourself concerning the examination of the complaint lodged with the CNIL and examined in accordance with provisions of Article 56.1 of the General Data Protection Regulation (GDPR).
The complaint was related to the conditions of processing of personal data of individuals that have created an account on the website More specifically, the complainant indicated having received his username and password in plain text by email following the creation of his account on this website.
These exchanges lead me, in agreement with other European data protection authorities concerned by the processing of data of individuals registered on to proceed to the closure of this complaint.
Indeed, in view of materials submitted, I note that you do not communicate to your users, nor store in your databases plaintext passwords.
Nonetheless, I should like to draw your attention on the malfunction identified concerning security of your authentication means.
Indeed, you put forward your compliance with security measures regarding passwords. In this regard, I take note that these do have a length of at least 8 characters and have to include at least 4 categories of characters (uppercase, lowercase, numbers and special characters), as indicated.
Nonetheless, you specify using a « captcha » mechanism as a complementary measure. Yet, such mechanism did not stem from materials submitted. My services have thus proceeded to informal checks on your website. They have not observed any « captcha » mechanism at the stage of user authentication but only a measure of access temporization which does not appear to be sufficient. Indeed, they have noticed that following 8 unsuccessful login attempts, the login page displayed the following message: "Too many login attempts. Please try again in 1 second".
RÉPUBLIQUE FRANÇAISE
3 Place de Fontenoy, TSA 80715 - 75334 PARIS CEDEX 07 - 01 53 73 22 22 - www.cnil.fr
Les données personnelles nécessaires à l'accomplissement des missions de la CNIL sont traitées dans des fichiers destinés à son usage exclusif.
Les personnes concernées peuvent exercer leurs droits informatique et Libertés en s'adressant au délégué à la protection des données (DPO) de la CNIL via un formulaire en ligne ou par courrier postal. Pour en savoir plus : www.cnil.fr/donnees-personnelles.
As a result, I invite you:
- to implement efficiently a « captcha » mechanism in order to prevent you from intensive and automated submissions attempts to login; and/or
- to enhance the measure of access temporization of 1 second currently on your website; the CNIL recommends in its deliberation no. 2017-012 of January 19th, 2017 the period of such measure to last more than 1 minute after 5 failed attempts, within a limit of 25 attempts per 24 hours.
Yours Sincerely,
Marie-Laure DENIS