DEV Community

Discussion on: What are the worst security practices you've ever witnessed?

Collapse
 
isaacdlyman profile image
Isaac Lyman

I was once aware of a website (trying to avoid details here) that stored hundreds of thousands of email addresses, passwords and social security numbers in plaintext and had a search bar for easy lookup. It didn't use HTTPS unless you checked a box on the login form, and the password I used would have been ridiculously easy to figure out.

I told multiple people that this was low hanging fruit for hackers. I don't know if anything changed.

Collapse
 
isaacdlyman profile image
Isaac Lyman

To clarify, I didn't choose that password, I just inherited it.