Hacker News new | ask | show | jobs
by cao825 5610 days ago
If they are worried about user experience and that is the main reason they do not encrypt - then why not at the very least use a version of encryption that the site can decrypt? Sure, the people who grab the data can run some cryptography programs on it and eventually come up with the algorithm, but it is a hell of a lot safer than plain text.
1 comments

We don't really know if they are encrypting the password while storing in the db.