3 ms·
Yes of course GDPR is not a law about plain text passwords, but (as the sibling comment points out), pretty much everybody considers the use of appropriate hash
by Recursing 7y ago
Yes of course GDPR is not a law about plain text passwords, but (as the sibling comment points out), pretty much everybody considers the use of appropriate hashing as a requirement to to ensure a level of security appropriate to the risk.
https://www.gamingtechlaw.com/2019/04/first-gdpr-fine-italy.html https://www.gamingtechlaw.com/2019/04/first-gdpr-fine-italy.... this fine specifically mentions password storage (among many other things)
Also see previous thread on HN: https://news.ycombinator.com/item?id=18531588 https://news.ycombinator.com/item?id=18531588
- micheljansen 7y agoOn top of that GDPR requires companies to notify customers of data breaches, which risks reputation damage. Another liability of shoddy security.