logoalt Hacker News

SoftTalkertoday at 2:04 PM1 replyview on HN

I wonder how many accounts have ever actually been compromised by a MITM reading passwords out of plaintext emails. I would guess it's very, very small.


Replies

shrikanttoday at 2:51 PM

I believe the bigger failure mode in that scenario is the fact that the site was storing user passwords in plaintext (either directly or effectively). Users tend to reuse passwords, so when there's a breach, more than just the user accounts for that site would be compromised.