Earlier quoted context omitted.
It is controversial but there is something in publicly posting already compromised long-living static credentials. I do not approve nor disapprove of this. It could be unethical, could be even illegal but still - it also may force to not rely on this security-through-obscurity approach and maybe actually start doing things right. Sadly, many people don't learn from theoretical implications - they just ignore those an…
There are degrees of everything. In an ideal world, they probably wouldn't have passwords at all and trust everyone who doesn't have explicit permission to just not use AIRLINE_CLUB or whatever. We don't live in that world. On the other hand, they probably don't want to use some complicated individualized password scheme because that's a headache for everyone. So they pick a happy medium that keeps out the casual web…
We had plaintext Internet once, but as it grew, it started to fail.So, now most of us cheer for TLS everywhere and believe it's a good idea. Don't see how this is any different.