Comment: Re:I like how they handle this stuff... (Score 1) 88
Do we actually know that they [b]stored[/b] unencrypted information, or only that attackers were able to extract it in some way?
Except for passwords, customer information [b]must[/b] be at least temporarily in a decrypted form to be used. That means that there exists a way to decrypt it. So if that were compromised, you could get decrypted data even though the [b]storage[/b] was encrypted.
Not saying the storage was encrypted, just pointing out that the extraction of unencrypted data doesn't prove that it was stored unencrypted.