• AggressivelyPassive
    link
    fedilink
    169 days ago

    We have a system that mails your password if you change it. It’s just for internal users, but still.

    • @Monument
      link
      English
      119 days ago

      That means those suckers are either stored plaintext or stored with decryption key that is somewhere within the server. Yeesh.

      • @Tja@programming.dev
        link
        fedilink
        99 days ago

        “if you change it”. It might send the email before storing it as a salted hash in the DB. Unlikely, but possible.