- Nov 9, 2003
- 143
- 0
- 76
The "forgot your password" page for a local online ticket vendor sends users their password in plain text. I just tested by making an account with a throwaway e-mail address. This is bothersome since a lot of people in the local community use the ticketing system and I can only imagine how they are storing credit card data.
I suppose they could be encrypting and decrypting the passwords, but they would have to store the key somewhere on their server.
Is it acceptable for a website to e-mail passwords in plain text to users?
Do you try to avoid doing business with organizations that don't seem to know how to store data securely?
Should I bring this up with the company?
I suppose they could be encrypting and decrypting the passwords, but they would have to store the key somewhere on their server.
Is it acceptable for a website to e-mail passwords in plain text to users?
Do you try to avoid doing business with organizations that don't seem to know how to store data securely?
Should I bring this up with the company?