100 Million Usernames, Passwords Leaked from Chinese web sites
english.caixin.cn
english.caixin.cn
Bullshit. Complete and utter bullshit, in fact. Encryption/hashing are your last line of defense. They're what you hope hold strong when they've blasted through everything else. Not having them is not the issue, it's simply indicative of a lack of security knowledge and forethought in everything else; poorly written apps tend to lack things like proper password storage, but that doesn't mean that proper password storage makes your app properly written.
Now, I'm not saying that proper password storage or encrypting user data aren't very important things -- I argue strongly for them all the time -- but locking your front door is just as important as having a strong safe for your valuables. If I can walk right in with SQL injection, arbitrary file reads, command injections, and other fun vectors, then you're largely screwed regardless.
There are many differences between a China Internet company and a U.S. one. One big difference is how heavily their leadership is weighted outside of the tech inner workings of the company. A second problem is the maturity of IT process management. Most Chinese programmers are serfs; lowly paid and no real voice. Managing the many security processes that a solid Internet site should be leveraging is several "business generations" away here in China.
Solving this one problem of storing passwords and handling auth correctly is attainable in the short term compared to the rest. The good news is the problem has already been solved and refined. In this context, it is not unreasonable requiring Internet sites that handle user auth to follow a very clean set of rules.
It pretty much shows they had no line of defense whatsoever. Password hashing is very easy. Even good, hard-to-crack, hashing is very easy.