Hacker News new | ask | show | jobs
by paulgb 6314 days ago
I agree that people do that, and that ideally a website would would not email someone their password for the simple reason that people do recycle passwords.

But, the onus here should really be on the user. If they are careless enough to use the same password for everything, they are indicating that they are willing to trade some security for convenience. In my opinion, emailing users their password is just another security/convenience trade-off. I'd be upset to get my password sent in plantext from my bank, but not an invite website.