I'm a big subscriber to broken windows theory; leaking raw errors and plain text passwords makes me think it's likely common practice...
I've reached out to them so hopefully they can get this sorted!
I've reached out to them so hopefully they can get this sorted!
I think that for all 'non-essential' sites it might be prudent to use a throwaway password each time. I think it might be an all too common practice on many a site.
After all, who can ever know that even a large site like Facebook or Twitter or Google or Hacker News is storing your password securely? You usually can't, so you may as well be cautious and not reuse passwords for any service.