3 ms·
Everyone is guessing if they are storing in plaintext or not. But that isn't the actual issue to learn from their mistake. They have publicly asserted what the
by omgitstom 12y ago
Everyone is guessing if they are storing in plaintext or not. But that isn't the actual issue to learn from their mistake. They have publicly asserted what they are doing (which is great information for a hacker), and chose a bad way to attempt to force users to reset their passwords because of a compromise. I would feel better if it was an email directly to mcgill faculty / staff. If you are building out a user management system, you need a way to disable accounts and force a password reset.
You never want to convey any information about the usernames, password, or state of the account _ever_. This is true for error messages during login, but can be applied to any messaging.