Hacker News new | ask | show | jobs
by PCheese 4444 days ago
The site just emailed me my password in cleartext when I used the "forgot password" option, so they must not be hashing them on their side. Seems like a terrible security practice.

The incident notification states "website user names and passwords could also have been accessed", so I guess this means cleartext passwords.