It's not really moot because I never assumed you were asserting that.
But you did just say that you would either not mention or flag as low priority (and the suggestion is grudgingly) a plain text passwords issue because "I would get my ass kicked by my clients and partners". I'll be honest - I wouldn't hire you if I had seen that written publicly like that :(
I sometimes think that one of the major failings in our industry is that we toe the corporate line and never stop to think like a cracker. That's why I have my job - because I do. Some people see plain text passwords as a "making life easier" issue, whereas for me it is a major weakness at the core of the security chain. Throw all you like in the way but, at the end of that day, the passwords are there in clear text waiting for me to find it. It doesn't matter how many different ways I can or cant compromise a site: all I need to do is do it once...
And anyway, my point was less about this specific issue than about how I think you address it wrong. The hashed passwords issue is one you can dress up for a client so they think they get value for money. If they get nothing except a green tick on the "critical errors" page then you leave them with the feeling that they are missing something. Hashing passwords should be fixed - and we can get them to fix it. And at the same time they get something meaningful from their audit :)
But you did just say that you would either not mention or flag as low priority (and the suggestion is grudgingly) a plain text passwords issue because "I would get my ass kicked by my clients and partners". I'll be honest - I wouldn't hire you if I had seen that written publicly like that :(
I sometimes think that one of the major failings in our industry is that we toe the corporate line and never stop to think like a cracker. That's why I have my job - because I do. Some people see plain text passwords as a "making life easier" issue, whereas for me it is a major weakness at the core of the security chain. Throw all you like in the way but, at the end of that day, the passwords are there in clear text waiting for me to find it. It doesn't matter how many different ways I can or cant compromise a site: all I need to do is do it once...
And anyway, my point was less about this specific issue than about how I think you address it wrong. The hashed passwords issue is one you can dress up for a client so they think they get value for money. If they get nothing except a green tick on the "critical errors" page then you leave them with the feeling that they are missing something. Hashing passwords should be fixed - and we can get them to fix it. And at the same time they get something meaningful from their audit :)