Hacker News new | ask | show | jobs
by chrischen 5115 days ago
Mainly because many Last.fm scrobbling clients relied on the legacy API that uses a person's password as a private key to authorize requests.

They send a token hashed with the password and they have to keep the original md5'd password on file in order to allow these clients to work.