April 14, 2009

McAfee apparently sends passwords to users in plaintext.

I have a very common name, which means I have a very common gmail address. I get a lot of mail for other people named David Reid. A lot of mail. Every once in a while a David Reid will sign up with my email address for some mailing list.

This morning I noticed an email from McAfee telling me how I could go about downloading some product that someone presumably just purchased. A few minutes later I get this email:

Picture 1 [REDACTED] by you.

So yeah, a so-called security company is storing and transmitting their customer's passwords in plaintext.

FUCKING AWESOME SECURITY FAIL.