This is pretty bad. I've received password reset emails from dreamhost in the past and the passwords are in plain text...I just renewed two days ago too.
At least Dreamhost says the Shell passwords are hashed, which makes sense.
I didn't know that about the plain text dreamhost web-panel passwords though.
Getting this fixed was already on our to-do list. This incident has moved it up to near the top of the list (competing with a few other security-related tasks).
Shell passwords - they're hashed, but are they salted? If not, can they be in future?
Thanks for your time.
If you could forward these articles to whoever's working on security, I'd appreciate it (and they're a good read): http://www.codinghorror.com/blog/2007/09/rainbow-hash-cracki... http://chargen.matasano.com/chargen/2007/9/7/enough-with-the...