samedi 28 février 2015

Should a password ever be presented in plain text to a user (On a website)? Is this illegal under UK Data protections act?



There is a website I use at work, external to our own. They have just presented with every employee with their plain text password and username via our internal website which requires our own logins.


I was wondering if this should be viable for a professional company (Either the external website company or my internal one) to store plain text passwords? And if so are they prosecutable under any law regarding how they store passwords?


Sorry I am very unaware of the way passwords should be handled and the law regarding them Thanks in advance





Aucun commentaire:

Enregistrer un commentaire