• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / Security and Privacy / Avoid websites that store your password in plaintext

Avoid websites that store your password in plaintext

2012-07-03 by Jason

If you forget your password to a website and your ‘forgot password’ request is answered with your password being emailed to you, there’s a problem there. Your password should at least be hashed with one-way encryption and stored in the database securely. Even though it’s convenient, it’s very bad security. As was exhibited by several database breaches recently, even hashed passwords are only a matter of time to solve with rainbow tables of known password-hash matches. It’s bad practice for users to use the same password across multiple web services but it is equally a responsibility of web service providers to secure the information they are entrusted with.

If you are looking for a little name-and-shame, you can visit Plain Text Offenders. The site collects screenshots of web services that send out your credentials in the clear. If it’s done at registration, it might not mean the database holds unhashed passwords but you better hope your email never gets broken into if it stores the keys to the kingdom. In addition, sending out your email across the wire in the clear cannot provide much assurance that it wasn’t picked up somewhere along the way. If the site sends your password to you on a password reset request instead of a reset link, then you should definitely have concerns.

Concerned enough? You can search PlainTextOffenders.com before you sign up for a new service to see if they have been listed as using bad practices with passwords.

A Google Chrome extension called Password Fail will automatically tell you if the site you are visiting has been registered as storing passwords in plain text. However, I’m not sure if the extension and associated site list is kept up-to-date.

Do you use any other resources to keep your accounts secure and avoid companies that implement bad practices?

Filed Under: Security and Privacy

Trending

  • PC Gaming Is Not Dead If You Have $2,800 For Razer’s New Laptop, Blade
    In Entertainment, Hardware, Gadgets, and Products
  • A Herculean Effort Against “Cyber Security” Malware in Windows Vista SP1
    In Security and Privacy, Software, Tech Solutions
  • A Week of Google Code, Day 1: touchfreeze
    In Software, Tech Solutions

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • Access to the resource [servershare] has been disallowed Access to the resource [servershare] has been disallowed
  • Read the Event Logs on Windows Server Core Read the Event Logs on Windows Server Core
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • How to ‘Unblock’ multiple files at a time with PowerShell How to 'Unblock' multiple files at a time with PowerShell
  • Setup your DFS namespace with DNS for compatibility in a mixed environment Setup your DFS namespace with DNS for compatibility in a mixed environment
  • How Virtual Reality Supports Mental Health Therapy How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting
  • Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams
  • customer contactless payment for drink with mobile phon at cafe counter bar,seller coffee shop accept payment by mobile.new normal lifestyle concept The Latest Innovations In Payment Technology
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in