Surely they don't send you your old password, but a freshly generated one? Then they could still be hashing them after emailing you.
Getting this fixed was already on our to-do list. This incident has moved it up to near the top of the list (competing with a few other security-related tasks).
Shell passwords - they're hashed, but are they salted? If not, can they be in future?
Thanks for your time.
If you could forward these articles to whoever's working on security, I'd appreciate it (and they're a good read): http://www.codinghorror.com/blog/2007/09/rainbow-hash-cracki... http://chargen.matasano.com/chargen/2007/9/7/enough-with-the...