I fondly remember the convenience advantages of plaintext password storage, both as a user and somebody supporting users.
Occasionally I wonder if there are user accounts in my life that are irrelevant enough I'd be happy to buy that convenience advantage with the necessary security risks ... but of course people's tendency towards password re-use makes that trade-off basically unofferable in any sort of ethical way.
At least bcrypt makes it moderately easy to not completely screw up the hashing part.
Occasionally I wonder if there are user accounts in my life that are irrelevant enough I'd be happy to buy that convenience advantage with the necessary security risks ... but of course people's tendency towards password re-use makes that trade-off basically unofferable in any sort of ethical way.
At least bcrypt makes it moderately easy to not completely screw up the hashing part.