Hacker News new | ask | show | jobs
by jergason 5423 days ago
You sent me my password in the confirmation email in plain text. Please fix this security hole ASAP by hashing the passwords.

Edit: The content looks great. Sorry, didn't mean to sound snarky, but that is a scary first impression of the site. I have some more comments that I tried to email to the contact email address, but my email was retured. Is there an email I can use to contact you or someone at the site?

2 comments

Thanks for the feedback. On my immediate to do list. No excuse, but I didn't build the site, and the process of trying to fix its bugs since I took it over while completely changing its focus has been especially onerous for me. Please use my personal email in my comment above.
Emailing a password plaintext in a confirmation email is completely orthogonal to whether or not it is hashed in the database! I agree that neither should be done, though.