Hacker News new | ask | show | jobs
by sveng 2956 days ago
Plain text passwords are a poor security practice, not fraud per se.

There’s no sense it was intentional, nor that any customers were impacted.

I used the Adobe example since 38 million customers had personal information exfiltrated in 2013 (including me).

Adobe knew better (or should have). But that still is not fraud.

They have enhanced their security practices since then, and I am still a customer of theirs.

1 comments

FWIW, at that time Adobe was already properly handling the password - what leaked was an old backup. Where passwords were hashed, just not properly.

Adobe did mess up on that one - it's just not on the same level, not even close. The main thing that makes it worse was that Adobe has a lot of customer data (likely unlike this guy, who probably didn't have many customers)