Hacker News new | ask | show | jobs
by ukandy 4067 days ago
"Because we helped with the website migration, we also had one of his passwords. As it turns out, he likes to use this password for his email address and other accounts as well.

We ended up with access to multiple private email accounts, one of his registrar accounts (NameCheap), his eBay account, SitePoint account and more."

That's as sketchy as it gets.

Go clean out your support tickets with customers passwords in now.

1 comments

All of those passwords are changed after migration. In this instance they weren't, as we had an active/open ticket with him.
All of your customers change the passwords to all of their other accounts after doing business with you?