I've never heard of Plenty of Fish, so I don't know what they do or what kind of user data they store. But I'll take a contrary point of view and say that for some services, light security is good enough.
Mailman, the mailing list management software that's widely used, emails you a password reminder once a month. They warn you when you sign up that your password is not really providing "real" security and not to use a valuable one.
This is the strategy he was employing... sending users a reminder of their password and keeping them engaged in the site.
Now, I do think they should tell people, when they are signing up, that they will get reminder emails of their password and not to use e.g. their online banking password here. If I know this going in, and depending on the nature of the site and what personal data they have, I might be OK with this.
Mailman, the mailing list management software that's widely used, emails you a password reminder once a month. They warn you when you sign up that your password is not really providing "real" security and not to use a valuable one.
This is the strategy he was employing... sending users a reminder of their password and keeping them engaged in the site.
Now, I do think they should tell people, when they are signing up, that they will get reminder emails of their password and not to use e.g. their online banking password here. If I know this going in, and depending on the nature of the site and what personal data they have, I might be OK with this.