51
moars42
7y

My brother singed up for a browser game.... They sent him his log data (including password) via email

Comments
  • 2
    Did you contact the devs to tell them to do therir job?
  • 2
    Submit them to the badpasswordpolicies Tumblr!
  • 5
    Well although that's very bad practice imo, it doesn't mean by default that they don't hash. Can hash the password, store it and send the original value through email all from the same script, right?
  • 4
    @linuxxx still insecure imho..
  • 2
    @sladuled Yeah agreed but just stating the fact that I'd you receive a password by email, it doesn't mean by default that it doesn't get hashed :)
  • 0
    Password he chose or a temporary password? Sending a temporary password is a practice done by many as it forces you indirectly to verify your mail.
  • 0
    His password
Add Comment