Hearing this, I changed my password and opened a ticket to have my account closed. About 15 minutes later, I got an email asking this:
May I have your username along with the first and third character of your password?
May I have your username along with the first and third character of your password?
It would be funny if they had hashes of every combination of passwords. Hopefully, it's just one.
This is pretty goofy. Among other things, those customer services will themselves be trivial to break, and are probably password-equivalent (use them with support to reset your real password).
This looks like a case of a company going out of its way to be marginally less secure than a typical non-secure framework application.