Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sadly a lot of prominent websites choose to store passwords in plain text or with a reversible encryption. It not until a hacker dumps their db or someone exposes it, we come to know about it. For me, I was really surprised to find even Discover Bank storing their customer's passwords in plain text. I did a write up about it: http://www.techflock.com/discover-card-storing-passwords-in-...

YC Disc: http://news.ycombinator.com/item?id=4102387



There is a review process by a disinterested internal party that's given licence to shoot anything down that isn't secure enough by their standards, so I agree with the parent poster that this is unlikely (but not impossible, if someone was doing something really stupid).


I agree that a lot of websites store passwords in plain text. Mostly it's because these companies are not technical. They have IT departments but are companies like a bank (As in the case of Discover, or hardware manufacturers or govt. agencies). I just hold a tech company like Yahoo to a much higher standards.

In addition, a little bird told me that these passwords are not being accepted by the yahoo servers. The whole thing doesn't pass the smell test.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: