Hacker News new | ask | show | jobs
by Istof 4415 days ago
If you use the "forget password" link and receive your old password by email, then they more then likely have your plain-text password unless they crack it on the fly?
1 comments

If you receive your old password then yes, they do have it stored in plaintext. Usually these days forgotten password pages just ask you to create a new one, but if they don't that's a sure sign.
Not so sure; it could still be encrypted (also bad practice)

Still, if you receive your password back, that is a giant red sign screaming insecurity