Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> 2. Emailing them in plain text.

Even if the password were irreversibly encrypted, if I can read your e-mail, I can still access your account in most systems. I can reset your password, and either follow the link they e-mail you, or see the random password they generated for you.

I think #2 is more on you for accessing your e-mail securely, and less on Pingdom. Pingdom is only saving a hacker a little bit of time.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: