1. Exquisite Tweets from @troyhunt, @UKTesco

    tomscottCollected by tomscott

    Click the "Why it's safe" link on @UKTesco and.... a browser warning about the page having insecure content is returned.

    Reply Retweet Favorite

    troyhunt

    Troy Hunt

  2. @troyhunt Let me assure you that all customer passwords are stored securely & in line with industry standards across online retailers.

    Reply Retweet Favorite

    UKTesco

    Tesco Customer Care

  3. .@UKTesco let me assure you that if you are emailing passwords to customers, you are well short of industry standards on a number of fronts.

    Reply Retweet Favorite

    troyhunt

    Troy Hunt

  4. @troyhunt Passwords are stored in a secure way. They’re only copied into plain text when pasted automatically into a password reminder mail.

    Reply Retweet Favorite

    UKTesco

    Tesco Customer Care

  5. .@UKTesco what "secure way"? Clearly they're not hashed & regardless, you're sending them in plain text over an insecure channel (email).

    Reply Retweet Favorite

    troyhunt

    Troy Hunt