Fasthosts exposed their customer's passwords:
http://www.theregister.co.uk/2007/10/18/fasthost_police_hack_investigation/
I post this blog not to rag on them - not at all.
I post this because I take issue with a quote they provided to the interviewer:
"Historically, Internet companies have rarely encrypted passwords to aid customer service"
That is nonsense. I take issue with them speaking as if they represent the entire hosting community and implying that they know what everyone else does. I take issue with them trying to lower the seriousness of their error by claiming that other hosts are just as unsecure.
Total nonsense. I can't speak for every host (as they tried to do) but I can say that at ORCS Web we definitely encrypt all sensitive data - not just passwords but other things too. Encryption is not rocket science. Especially using .Net - developing code to store secure information is not that hard.
Shame on them for trying to lump all hosts together in this mess. If I had to guess - and it would be no more than a guess - I bet most hosts DO encrypt passwords. If they don't, well, I think they are asking for trouble and hopefully they are made aware of this issue and it makes them take immediate action - for their own sake and the sake of their customers.
~Brad Kingsley
ASPInsider, MCSE
http://www.orcsweb.com/
Managed Complex Hosting
#1 in Service and Support