|
|
|
|
|
by tptacek
6025 days ago
|
|
There is a difference between storing plaintext passwords and actually losing them, and as much as I hate to give someone a pass on insecure password storage (it is, apparently, all I ever talk about here), you have to be intellectually honest. And, like I say every time this comes up, FedEx and several banks also store plaintext passwords. 37signals no longer stores easily attacked passwords. |
|
I was intellectually honest. I explicitly said they didn't actually lose them.
37signals no longer stores easily attacked passwords.
I was under the impression that this was true as well. However I just checked and I got my Backpack password emailed to me in plain text. So at least the Backpack application is still incorrect.