2 ms·
Encrypted or not, the fact that a company is able to send you your original password shows that they are not playing with a full deck.
by Mark_B 17y ago
Encrypted or not, the fact that a company is able to send you your original password shows that they are not playing with a full deck.
- rmorrison 17y agoYeah, I suppose I should clarify. Instead of storing the plaintext or encrypted version of the password, they should store a hash of the password. Since, if/when the database gets compromised, it's even more difficult for the attacker to retrieve the passwords. If the passwords are just encrypted, once the attacker figures out the algorithm, then all of the passwords will be compromised. A hash, on the other hand, would require each account password to be broken individually.
- keefe 17y agothe thing that pisses me off most is... I sign up for some website and a few minutes later I get some email - hey welcome to site X your username is Y and your password is Z... WHAT THE FUCK