Among their many failures, I am still shocked that the notes section for each password was not encrypted. All kinds of assumed-safe info will be in there from secret question answers to former passwords and account numbers. What fool of a project manager pushed for that?