If a "forgot your password?" page emails your old password, is that definitive proof that they have
- by S. Michaels
When a site emails your old password, as opposed to requiring you to reset it on the site, I'm wondering what that implies about their security measures.
Does this mean that they store the password in plain text for their own convenience or could they still use encryption on the password?