Hacker News new | ask | show | jobs
by kevincox 2029 days ago
To be absolutely pedantic including the password in the signup email doesn't mean that they are storing it in plain text as they could have just generated the email then thrown away the password.

However I would bet that frequently they do, frequently the emails are logged for a substantial period of time and it isn't a best practice anyways.

1 comments

Considering that emails fly through a bunch of MTAs and also occasionally aren't transmitted via TLS, none of it matters, your password is public by the time you see the email