Click the "Why it's safe" link on @UKTesco and.... a browser warning about the page having insecure content is returned.
#1 4:17am Jul 29th 2012 via MetroTwit
Reply Retweet Favorite
troyhunt
Troy Hunt
@troyhunt Let me assure you that all customer passwords are stored securely & in line with industry standards across online retailers.
#2 11:26am Jul 29th 2012 via Conversocial in reply to troyhunt
UKTesco
Tesco Customer Care
.@UKTesco let me assure you that if you are emailing passwords to customers, you are well short of industry standards on a number of fronts.
#3 11:29am Jul 29th 2012 via Twitter for iPad in reply to UKTesco
@troyhunt Passwords are stored in a secure way. They’re only copied into plain text when pasted automatically into a password reminder mail.
#4 12:41pm Jul 29th 2012 via Conversocial in reply to troyhunt
.@UKTesco what "secure way"? Clearly they're not hashed & regardless, you're sending them in plain text over an insecure channel (email).
#5 12:53pm Jul 29th 2012 via Twitter for iPad in reply to UKTesco