Plaintext Passwords, Legally Secured
Description
A dark-mode Twitter thread screenshot shows user freakyclown describing a Virgin Media account recovery flow where, after forgetting account details, a representative says the password will be posted by mail. The user says the letter contains an old password they recognized on sight, concluding that Virgin Media stores passwords in plain text and does not reset them, then criticizes @virginmedia. Below, a verified Virgin Media reply says, "Posting it to you is secure, as it's illegal to open someone else's mail. ^JGS" The meme highlights a security failure where legal deterrence is treated as a substitute for proper password hashing, reset flows, and credential handling.
Comments
13Comment deleted
Nothing says defense in depth like replacing bcrypt with the federal crime of opening envelopes.
Jesus, someone see if that's real Comment deleted
https://twitter.com/virginmedia/status/1162756227132198914 Comment deleted
damn. I hope that representative was fired. Comment deleted
mother of Comment deleted
no fucking way lmfao Comment deleted
is it? Comment deleted
Banning weapons makes sense because it makes illegal for criminals to have guns. Comment deleted
What is ^JGS? Comment deleted
Initials of the team support member I guess Comment deleted
My guess as well, it’s a common practice Comment deleted
Thanks! Comment deleted
Employer of that company be like: E: Do you promise to not reading other's mail and forget every password you read? A: maybe... E: GREAT! YOU GOT A JOB!!! Comment deleted