etnull wrote:gengreen wrote:Right. Yes it is
I disagree, being worry about a password stored in clear is a security mistake at the first place.
Never password reuse.
The question was not about worrying or best practices. The question was - is it bad or not, and yes it is bad no matter how skillful you are in shifting blame to your users. 50% of users do reuse their passwords, maybe not on this forum but still.
If it was only the users the problem ok... but even IT professional are reusing (and other sector), we should insist on this as much as possible.
This problem is older than year 2000 and will remain for long, probably forever, despite an available solution of never reuse password.
Being said, pushing people to understand that hash/crypt password of the forum wouldn't be a concern if at the first place, password was uniq, saying it can't harm but saying the dev of Gentoo are doing bad practice do harm.