GMBill.com CEO Responds to 'Plaintext Passwords' Tweet

SAN FRANCISCO — A tweet by an adult industry journalist spread like wildfire last week, bringing mild hysteria to message boards.

The tweet made by Violet Blue said: “One of the top adult affiliate credit card processing payout companies is storing passwords in plaintext.”

On Saturday, Blue confided to XBIZ that the top affiliate processor discussed in the tweet was GMBill.com.

“All the passwords are stored in plaintext on the server and in user accounts,” she said.

Blue went on to discuss another concern: “They only do payouts via wire transfer/EFT, and so that means everyone's bank account credentials are 99 percent likely to be stored in plaintext on the server too.”

“One not-terribly-clever hacker could do a lot of damage with tools readily available online,” she emphasized to XBIZ.

Sunday morning, GMBill’s CEO and founder, Garion Hall — also CEO and founder of AbbyWinters.com — responded to Blue’s tweet over visible plaintext passwords.

“[Blue] is incorrect,” Hall told XBIZ. “All passwords are stored encrypted but are decrypted when the user logs in — for example, once a user successfully authenticates and logs in, their password is decrypted.” Hall continued saying that the process “is widely considered an effective security practice.

“GMBill.com acknowledges the practice of showing users their passwords on-screen is falling out of favor — due to the risk of ‘shoulder surfing’ or a malicious user accessing browser cache), but is still common practice,” he said.

Hall noted he could come up with numerous examples over this but pointed to iCloud as one.

“For example, Apple’s Keychain also shows users passwords of sites and networks they have access to, after entering their admin password,” he said. “This is considered low risk, as at most it affects a single user.”  

Hall also addressed Blue’s accusation that affiliate’s EFT, or wire, bank account details are at risk.

“These are the same details every company places on invoices and some websites to customers,” Hall said. “Access is secured through standard security practices; by taint checking of all database inputs, all code being encrypted — including database access credentials — and fine-grained privilege separation for database user accounts.

“However, we have taken these accusations as a reminder that security never sleeps,” he said. “We have added velocity controls to the affiliate login process, blanked previously visible passwords, and even-more-thoroughly encrypted affiliate bank details. These changes will be released to production servers as a priority.”

Hall emphasized to XBIZ that there was no breach at GMBill; he also said he invites concerned parties to direct specific questions to him at garion@gmbill.com.

“GMBill.com conducts regular log scans to identify suspicious activity and has undertaken an especially close look in light of these accusations. We confirm there has been no breach of our security systems, no affiliate, client or customer data has been accessed by unauthorized parties, and all security measures in place continue to function appropriately.”

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Ukrainian Parliament Rejects Porn Decriminalization Bill

The Verkhovna Rada, Ukraine’s parliament, on Thursday voted against passage of a bill that would have decriminalized the creation and distribution of pornography in that country — an activity that currently carries a prison sentence of three to five years.

FSC Launches Pride Fundraising Drive

The Free Speech Coalition (FSC) has launched its Pride Fundraising Drive to support its efforts on behalf of the LGBTQ+ community.

Cultpix Debuts AI-Generated Vintage Adult Films at Cannes

At this year’s Cannes Film Festival, B-movie streaming service Cultpix debuted a collection of AI-generated short films drawn from erotic magazine photo spreads published 50 years ago.

Ofcom Fines Youngtek Solutions $800K for AV Noncompliance

U.K. media regulator Ofcom on Wednesday imposed fines totaling 600,000 pounds (more than $800,000) against adult site operator Youngtek Solutions for failing to implement age checks and respond to information requests as required for compliance with the Online Safety Act.

Pornhub Launches Lesbian Site 'Pornhub Sapphic'

Pornhub has launched Pornhub Sapphic, a site dedicated to female and non-binary content and creators.

Brazil Invites Public Input on AV Guidelines

Brazil’s National Data Protection Authority (ANPD) on Friday launched a public consultation on developing guidelines for age verification mechanisms under the country’s Digital Statute for Children and Adolescents (Digital ECA), which requires adult websites to age-verify users located in Brazil.

Paysite Confidential: Inside the Creator Economy's Shift Toward Ownership

For years, the adult industry’s creator economy has been defined by platforms — powerful engines of discovery, monetization and scale that reshaped how performers connect with their audiences.

Senator Urges DOJ to Crack Down on 'Obscenity,' Attacks OnlyFans

U.S. Senator Jim Banks of Indiana this week urged Acting Attorney General Todd Blanche to reestablish the Department of Justice’s defunct Obscenity Prosecution Task Force in a letter that targets OnlyFans while repeatedly conflating “obscenity” with legal adult content.

UN Experts Urge US, Canada to Prosecute Aylo, Others for 'Exploitation'

GENEVA – The United Nations Office of the High Commissioner for Human Rights (OHCHR) has issued a press release in which two U.N. special rapporteurs, cited as experts, accuse Aylo and other companies of complicity in sexual exploitation.

Kickstarter Revokes New Rules Banning Fundraising for Adult Content, Products

Crowdfunding platform Kickstarter announced Tuesday that it has reversed its recent decision to impose new “Mature Content” rules banning projects that involve adult content and sextech.

Show More