Poor Password Practice – Some Utilities Use Service that Sends Passwords in Plain Text
After a concerted attempt at responsible disclosure to the vendor who designed his power company’s website, an anonymous security researcher shares his September 2018 discovery of poor password practices. According to ArsTechnica, the researcher reached out to SEDC, an Atlanta firm that provides utility software solutions, after the troubling discovery that his power company’s website was sending plain-text passwords in-lieu of a reset for forgotten credentials.