https://chrome.google.com/webstore/detail/ockgeenjbijlgilppf...
Either the user is using the same password on multiple sites. Then this would be a real security issue, independent of the fact if some of the sites store the password in plaintext.
Or the user is using different passwords for different sites. Then you don't really need to care how a single site handles your password.
I love this idea!
Nevertheless, the vast majority of users do - and that's unlikely to change in the near future. It's just too easy.
Many users (the majority? I've seen no statistics for this, but everybody I know falls into this group) do, however, keep several passwords, and assign them to sites based on a combination of 1) how likely the site is to compromise the password (sites that email out plaintext score very poorly) and 2) how much the user cares about the security of that particular account. Which suggests the following use case for fourk's hypothetical plugin: user wants to know what password to use, sees that fooneti.cs is one of those sites that stores easily recoverable passwords, and chooses to use one of the disposable ones.
Also, it's a fact that a lot of users reuse passwords. Pretending that it's not the case or claiming that it's the wrong thing to do is pointless. Good security should address the real world, not some silly idealized one.
Sure, but if I'm choosing between two sites that offer a similar service, knowing that one is insecure is going to strongly influence me to use the other. It's information that's worth having.
Although, this brings up a point - if the list is crowdsourced, companies may have incentives to report their competitors are insecure. There would have to be some way of erasing "insecure!" votes - but then you end up relying on a (hopefully benevolent) dictator.
What's a good solution? pg can't be everywhere at once!
A) Incompetent B) Don't give a shit about their users data privacy C) Both of the above.
It is not uncommon for databases to be stolen via lost laptops, human error, or sloppy security. When this happens, I would prefer that the database not contain my plaintext password.
If someone obtains my password through such a leak, it won't help me that I've used a distinct password for that website.
It's bad news when a bank leaks their customer list. It's catastrophic news when a bank leaks their customer passwords.
If you don't store the passwords in the first place, they can't be leaked.