Hacker News new | ask | show | jobs
by dnskw 4704 days ago
They could have encrypted them and then decrypt if they want to view them.
1 comments

But that's still just as bad. It doesn't matter if one person or a thousand people reads someone else's password in plain text. It's still technically a breach in security regardless of if they work for the company or not.
Yes it is bad, but its better than storing them in plain text in the database.