Coms.com (formerly ADSL24) were able to tell me my portal password over the phone (which I already knew, and without doing a security check). This means it's either stored as plain text (likely) or with 2-way encryption, rather than hashed.
Is this standard practice amongst ADSL suppliers? It certainly isn't for any companies I develop web apps for...



Print Thread
reywob