3 ms·
The worst part is that it comes by email, which is plaintext everywhere. However, "encrypted in a database" is not "plaintext". It's certainly not ideal or rec
by pdubs 14y ago
The worst part is that it comes by email, which is plaintext everywhere.
However, "encrypted in a database" is not "plaintext". It's certainly not ideal or recommended, that's for sure, but it's not the worst way to handle passwords. If properly implemented, a bunch of AES encrypted passwords without a key are nearly as useless to an adversary as a bunch of bcrypt hashes.
Just don't reuse passwords (at least for accounts you care about) and it really doesn't matter.