Got this in an email this morning…
This weekend we discovered that Gawker Media’s servers were compromised,
resulting in a security breach at Lifehacker, Gizmodo, Gawker, Jezebel,
io9, Jalopnik, Kotaku, Deadspin, and Fleshbot. As a result, the user name
and password associated with your comment account were released on the
internet. If you’re a commenter on any of our sites, you probably have
several questions.
Why yes, I do have some questions…
- Why are you storing passwords in a form that means people can “release them onto the Internet”?
- Why am I being told on Tuesday about stuff that happened on Saturday?
#include "facepalm.h"It’s a bit poor that websites devoted to telling people common-sense manage to fail at it themselves. It’s very very simple do not store user passwords in plaintext. User forgets their password? You send them a time-limited token to allow them to reset it.
This is also why it’s bad to type in your Facebook/Twitter/Googlemail details into those “import your contacts” forms on websites.
Never mind, nobody is daft enough to use the same password on multiple websites, right?

