4 ms·
For big sites, I have a hard time blaming it on a bad developer. Early in my career, I worked for a company that stored it's passwords in plain-text. I suggeste
by ssharp 10y ago
For big sites, I have a hard time blaming it on a bad developer. Early in my career, I worked for a company that stored it's passwords in plain-text. I suggested on many occasions stop doing this and was always told no because the site had an older audience and they wanted to make it easy to send password reminders, which also meant they were emailing passwords in plain-text. This came from the tech director and CEO and none of the other devs seemed to care.
A few years after I left, their DB was compromised, so someone got a list of email addresses with clear text passwords.