3 ms·
People reuse usernames and passwords, so even though it is painless, now they will have a database of usernames and passwords which can probably be used in a lo
by brfox 17y ago
People reuse usernames and passwords, so even though it is painless, now they will have a database of usernames and passwords which can probably be used in a lot of places. Thus, I only sign up for new things rarely and only for things in which I suspect I will need to use frequently.
- bdmac97 17y agoHmm... I guess you have a point there. It's frustrating a bit as a developer because in all likelihood if they've done their jobs as developers they DON'T have access to your password at all. The problem is how do you trust a new site when there are obviously some (many?) out there that still use plaintext for passwords? Anyone have a solution for that? Some type of security audit w/a badge that your site can display saying "Hey, we DON'T store your password or have access to it!" What would you say if they instead used some form of OpenID system (RPX Now or something) so you didn't have to give them your password? Would that help?
- mildweed 17y agoWe PHP CRYPT() those passwords and never see them. I am disappointed you think we'd store passwords in plaintext.