Jon Canady

 

Plaintext Passwords Make Me Weep Hot Tears of Shame

All around cool guy Chris Green mentions via twitter:

I HATE it when you register a new account and the website emails you the login and password. STOP DOING THAT! ...WORDPRESS.COM!

Sending Vitals in Plaintext Is So Last Year

A lot of people don't care about this, but they probably should. Sending out an email with your password sitting right in in means anyone that happens to be watching network traffic can read your password. It's like sending cash through the postal service: asking for trouble.

If you're not worried about that (I'm not) then worry about one of your idiot friends ganking your password out of your inbox and posting various horrible, NSFW images on your blog.

Maybe I just need better friends.

Storing Vitals in Plaintext Should Be a Mortal Sin

A lot of people don't care about this, but they absolutely should. In the worst case, someone cracks Reddit's database and steals a whole slew of username/password combinations.

Or Reddit accidentally posts a dump online.

Or a Reddit intern leaves a backup tape in a car that gets stolen.

If you're not too worried, replace "Reddit" with "Government" above and remember that all of these things have happened already.

Seriously kids, it's 2009. You think we'd have figured out this amateur-hour bullshit by now.