sean@seanmccambridge.com   (843) 696-7237
RSS feed

Best of the Web should encrypt passwords

January 5, 2010

I just signed up for Best of the Web because I’m finally taking my own advice and working on some SEO.  In their confirmation email, they sent my username and password.  That is not secure.  Since they just sent my password to my email account, my guess is they probably store it in their database not just unsalted but unencrypted whatsoever.

This is bad practice.  You would think a site as big as BOTW would know better.

Meanwhile, my session expired and I was automagically logged out with a JavaScript alert to make me feel safe.  Too bad a real hacker could sniff my connection and have my password already.

Thoughts?

 

Comments

No comments yet.

 

I appreciate your feedback. Comments are moderated. Email is required but won't be printed. Include your website if you have one.

Website question?
Just ask! :D

(843) 696-7237

sean@seanmccambridge.com

Twitter: @mccambridge

A LOT OF PEOPLE HAVE ASKED about the background photo on this site. It was taken on the beach by Fort Moultrie on the harbor side of Sullivan's Island, SC. The old, wooden sea wall has been there as long as I've lived in Charleston. The beach is a great place to watch the ships and shrimpers come in and has one of the best views of downtown Charleston.