30% of Sites Store Plain Text Passwords
readwriteweb.com
readwriteweb.com
Uh huh.
I worked at a company that had properly encrypted passwords, but the customer support people would just ask the user for their username/password and login through the front door. Once I found out about that, I implemented a simple yet secured impersonate system and it has served us very well.
The way I set it up is that the user must first log in to an administrator-level account before they can impersonate another user by entering a username or ID.
The overall goal is a "community documentation of bad web authentication practices," but at a minimum it would be great to compile a list of websites that send out plaintext passwords when a user forgets their password. Anyone interested?
Of course that doesn't mean a third of all sites - just a third of sites with lousy enough security that this chap could break in to them (presumably more SQL injections).
Frankly, I'm surprised the percentage isn't higher if the sites are badly maintained enough to let this guy in through another exploit.
Doesn't mailman email out monthly reminders of passwords, with passwords in plain text? I know you can opt out of the reminders, but it's default behaviour.
1) Create account with "throw-away" password
2) Invoke "recover password" functionality
3) Check email to see if they send you your password in the mail (doh), or if they ask you to log in to create new one (yay)
It's still a good indicator, and if you do get back that throw-away password then you know to be extra careful/give the site a miss.
This doesn't apply to, say, the New York Times, of course; but accounts that you care about should have decent passwords.