3 ms·
> as a pentester was that "storing passwords in plaintext" would be a low-severity finding I suspect that's because you're viewing the situation as a pentester
by Jwarder 9y ago
> as a pentester was that "storing passwords in plaintext" would be a low-severity finding
I suspect that's because you're viewing the situation as a pentester not a user. A plaintext password (on its own) doesn't do a pentester much good until they've already gained control of the system. However, once someone has control of the system then plaintext passwords are a threat to users because a lot of people are vulnerable to common password reuse.