Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

One of the comments in the blog is: "Just signed up for pingdom and they sent me my password via email in clear. Great!"

I signed up to check if they really do. What pingdom does upon sign-up with your email id they send a password via email.

I have a high opinion of pingdom & I was expecting them to enforce change of password during first login, but that did not happen!



Even if they enforced a password change it wouldn't help if they are storing them in plaintext.


A one-time password is usually generated and emailed, then hashed and stored, so not generally stored in plaintext.


It is called a one time password for a reason. Since it has been sent out via some medium in plain text, it is a good practice to force change password on next login.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: