I wasn’t trying to claim what was happening here, simply that one (extremely) bad practice increases the chance of another.
They have said it is being hashed for storage: forums.larian.com/ubbthreads.php?ubb=showflat&…
I can’t fault the OP though, if I received such an email I would assume it is stored in plain text and be similarly upset.
KairuByte@lemmy.dbzer0.com 1 year ago
MajorHavoc@lemmy.world 1 year ago
Reversible hashed password storage isn’t meaningfully better than clear text.
A reversible hash provides a paper thin layer of protection against accidental disclosure. A one way hash is widely considered the bare minimum for password storage.
Anyone claiming a password has been protected, and then being able to produce the original password, is justly subject to ridicule in security communities.
Bitrot@lemmy.sdf.org 1 year ago
The one they were sending at registration was prior to hashing.
MajorHavoc@lemmy.world 1 year ago
That’s technically less terrible, then.
Good for them.