3 ms·
You said "37signals stores passwords in plain text in their database" You have no way of knowing how they store their data! And saying something like this is l
by ten7 17y ago
You said "37signals stores passwords in plain text in their database"
You have no way of knowing how they store their data! And saying something like this is ludicrous and insulting, IMHo. Sure, they emailed you your password. That doesn't mean the password was stored in "plain text"... it just means it was stored. Yes, a one way hash would be better, but they stored the password. That doesn't mean the password was not encrypted when it was stored. It also does not mean the encryption key and the storage database are not on different servers -- which would be harder to crack, since it would mean two servers would have to be compromised. There is the possibility that they used two way encryption. That exists, you know...
Just sayin'...
- thorax 17y agoOccam's razor says to me that if they didn't take the time to make one-way hashes, they're not doing anything especially clever with the storage. Certainly no dual-machine way of handling them because that's surely more complicated than using SHA1 or MD5.