I worked on a project once where users' passwords were stored as plain text. Even worse, though, the system would often send automatic mailings with the password at the bottom, in plain text, because users virtually never remembered them. This included e-mails to the guy in charge, who I'm almost certain would sometimes forward these messages on to the relevant people, with his password visible. Anyone could have logged in as him and done god knows what in that system.
I whined about it more than once, but no one seemed to think it mattered. OK then, I guess? Don't come crying to me.
47
u/[deleted] Mar 08 '16
[deleted]