Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>The encryption is most likely enough to be within GDPR compliance. //

Why do you think that, allowing staff to read plaintext passwords is contrary to standard security practice; companies are expected to make reasonable effort to secure PII and allowing staff to read your password doesn't appear to be "reasonable effort" by even the casualist of readings.

I don't think the EU courts are that stupid.

FWIW I don't think there is a case here particularly, as it appears to be a genuine error and being fixed.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: