23 ms·
If they sent it to you at signup, it doesn't necessarily mean that they're storing it without encryption.
by 5vforest 14y ago
If they sent it to you at signup, it doesn't necessarily mean that they're storing it without encryption.
- Smerity 14y agoEmail isn't sent in an encrypted form by default so this still indicates a serious concern. Either they a) don't hash passwords or b) are happy sending passwords in cleartext across the internet to machines that you don't directly control.
- Cushman 14y agoGiven that it's http://www.easel.ly/ http://www.easel.ly/ and not https://www.easel.ly/ https://www.easel.ly/, b) kind of goes without saying.
- deelowe 14y agoThe only time a server should see a password is when it's generating or comparing against the salted hash using something like bcrypt. There should never be a way for a server to retrieve the plain text password. Ever.
- deleted 14y ago[deleted]
- jvm 14y agoThe other replies to this comment are correct, but just to be clear: USER PASSWORDS SHOULD NEVER BE STORED ON THE SERVER, EVEN IN ENCRYPTED FORM.
- TazeTSchnitzel 14y agoCorrect, you should hash them. Preferably with an algorithm designed for password hashing.