Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Sorry, I didn't clarify: they showed in plaintext the password that I supplied and emailed my password back to me.


Emailing a password after registration does not, in itself, indicate that passwords are being stored in plain text.


My secure password being sent across the open net in an e-mail is reason enough to shame the company doing that.


While much is made about passwords being sent across the open net, almost every site short of banks allow you to reset a password with an email, which is a close to identical problem.


Reset links can have an expiration time.


In addition to this, the open source distribution of Wordpress hashes passwords.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: