Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah... they could be doing that. But these are the same people that implemented the forced password change in the first place. The overwhelming likelihood is that they're storing them in plain text, and the jury might still be out on whether that plain text is world-readable or not.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: