Skip to content

Ask HN: Websites emailing passwords in plain text – anything to do?

6 pointsmaximente4 comments
On HN

per title, i've had two websites this week send forgotten passwords in plain text over email which would imply it's stored as plain text.

is there anything positive one can do here?

Comments

Ask them to fix their site. Give them a few months. Get them on the PlainTextOffenders list if they won't fix their site. [1]

[1] - https://github.com/plaintextoffenders/plaintextoffenders

I'd avoid those sites and ensure passwords are unique (using something like 1Password). If you want, you could also send the maintainers a few links on best practice.

Reset password. Hope they don’t mail the password again

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.