4 ms·
Well, that's not what this is about. This is about sending the password (from the client to the sever, to log in) in plain text, and that's easy to verify by ju
by samdk 16y ago
Well, that's not what this is about. This is about sending the password (from the client to the sever, to log in) in plain text, and that's easy to verify by just sniffing your network traffic (which is what the author of this originally did).
It may be impossible to verify completely whether a site stores passwords in plain text without back-end access, but sites that do often send forgotten password emails in plain text too. If a site's doing that, it's a pretty good bet they're storing it in plain text. (And if they're not, they're using a pretty insecure storage scheme anyway. Websites should store salted cryptographic hashes of passwords, not the passwords themselves.)