They knew the "plugin" stores passwords in clear text and still chose to use it.
I don't care if they had a plan to move away from it. That's not good enough.
Seriously how fucking hard is it to do things properly?
I don't care if they had a plan to move away from it. That's not good enough.
Seriously how fucking hard is it to do things properly?
Makes a big case for OAuth in my mind.
Plenty of developers have no fuckin clue about basic security, so why would users of a tutorial site?