> Attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack.
Does this mean _current passwords ARE stored in plain text_??
IF this is the case, chances are it's because plaintext passwords more straightforward remediation and (statistically significantly) lower support times/costs. The convenience of this cannot be understated. BUT:
- Twitter just leaked that current passwords are stored in plain text
- Twitter just leaked that current passwords can be viewed by support tools used by employees susceptible to social engineering
Again, IF this is true, it's a lesson about the privacy and security risks ever-more-frequently associated with convenience (in this case internal convenience).