Larion Studios forum stores your passwords in unhashed plaintext. Don’t use a password there that you’ve used anywhere else.

  • tb_@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    8
    ·
    edit-2
    9 months ago

    But that still means they had your plaintext password at some point.

    Edit: which, as some replies suggest, may not actually be much of an issue.
    I’m still skeptical about them returning it, however.

    • voxel@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      1
      ·
      edit-2
      9 months ago

      hashing on client side is considered a bad idea and almost never done.
      you actually send your password “in plain text” every time you sign up.

      • wim@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        5
        ·
        9 months ago

        It’s not a bad idea and it is often done, just not in a browser/webapp context.

          • wim@lemmy.sdf.org
            link
            fedilink
            English
            arrow-up
            3
            ·
            edit-2
            9 months ago

            Sorry, I should have included an example in my comment to clarify, but I was in a rush.

            HMAC is a widely used technique relies on hashing of a shared secret for verifying authenticity and integrity of a message, for example.

    • Hexarei@programming.dev
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      2
      ·
      9 months ago

      Um. Yeah, because you provided it to them. They have to have it in plain text in order to hash it.