JoeBrowns.co.uk – Customer Services gave password over the phone
GF: I have forgotten my password and the forgotten password link doesn't work
CS: Not a problem, we should be able to give that to you, what is your email
GF: <<email address including spelling the name out twice>>
CS: I have found you, can you write this down
GF: Sure (sounding a bit surprised)
CS: << Password, character by character >>
GF: Thanks, that worked (me with my mouth open wide at hearing the result of the conversation)
CS: Oh your name is <<insert real name here>>
GF: Yes that's right
CS: Thank you and enjoy your day
Give the account potentially can have saved CC details in, order histories, delivery addresses, i was pretty shocked at the level of security on the site. The whole call lasted about 5 minutes, there no wait time. Plain text passwords on an eCommerce website... Asking for trouble!
Is it me, or is there something //slightly// wrong this this behaviour, or have I missed a trick?
Feel free to disprove me! As I would love to know how a company like Joe Browns can just give passwords away like that!
(Edit: Line breaks)