Saturday, May 15, 2010

IDs, passwords and emails

I don't know why it happens so often, but it does. You register for a new account on a site, pick a password for yourself and click Submit. Voila! The account is created.

But hey, wait. Did you notice that it just sent you an email with the password in plaintext, just in case you forget it later?

There's nothing more frustrating than realizing in one glance that:
1. Your password is being stored in plaintext on their system.
2. Your password was posted on public insecure internet in plaintext.
3. Your email provider has a copy of that email, with the password in plaintext.