Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Even setting aside the years they had to become compliant, it still wasn't a good idea to store passwords in plain text before GDPR.


Regardless of the law, it's completely irresponsible to store passwords in plaintext, and it's been widely considered so for decades - the company's behavior here is inexcusable, and I really can't understand why anyone would try to defend it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: