Shop.charliesoap.com sending unencypted passwords to browsers
https://news.ycombinator.com/item?id=4785813Yep. I just noticed this as I logged in to update my email address. I saw that the password field was actually populated with something so I checked the markup. Sure enough, there was my [fortunately unique and randomly-generated] password in plain text. That means whoever coded their shopping Web site is most likely storing passwords in plain text in a database. I've sent them two messages about this.