1
Ask HN: How to out a MAJOR online company storing passwords in plaintext?
I recently became aware of a major online hotel broker that stores passwords as plaintext in their system. The management is aware of the technical risks and liabilities but has pushed off technical fixes for YEARS. Furthermore, the features of the website make it obvious that this could be q very valuable attack vector as the reset feature emails you your current plain text password.
So the question is: what is the ethical way to raise the issue and force their hand in a fix?
(Sorry for brevity and spelling; mobile on holiday)