back
8 comments
We really need a browser addon that has a catalog of these services. When you go to sign up to one of them, it'll alert you with "This site stores your password in plaintext!"
Such a common design pattern. Is the "here is your one-time PIN to change password" really that much better, if the email account can be compromised?
It isn't. But a better site would let you click the link in the email, and then proceed to ask security questions or identify you in some other way.
I was thinking the same thing. Any MITM can intercept the reset-password link email and set the password to whatever they want then login with the email.
The difference is usually time - your actual password sitting in plaintext in your inbox vs a code that's only valid for 10min-24h. In my opinion, it's marginally more likely for a full point-in-time comprimise of an email account. A credential that has already expired is less useful than one still valid.

Granted, if an attacker can trigger a password reset and also have persistant access to an inbox, there's still an issue there, but it's at least less bad.

Yes, the only real difference is passive harvesting of email/passwords. Anything targeted is similarly insecure.
It doesn't look like the list has been updated since 2021. Perhaps some of the offenders have changed their ways already.
Very surprised to see archlinux.org on there. Would’ve thought they would know better about security.