Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The blog is not accurate. They only send you your password the first time, when you create it. They store a hash, all you can do afterwards is reset it.

http://support.wordpress.com/passwords/



Makes me feel a bit better about WP. They are still storing the passwords temporarily in 2-way, so it's less of a hacking risk for the new account, though potentially a hacking opportunity for other websites used by the same user.

I still can't say I approve of their implementation though. What if someone is looking over your shoulder when you click the link to see your new account has been created and your password is right there for someone watching?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: