Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I didn’t get that this time at least. It’s worth pointing out that while that’s not great, if they send the password before encrypting it for saving in the database and only send it internally to their own mail server then there’s little security risk. But it’s not best practise as it trains users to expect it from other sites.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: