Passwords exposed in Click Frenzy security slip(zdnet.com)
zdnet.com
Passwords exposed in Click Frenzy security slip
http://www.zdnet.com/password-exposed-in-click-frenzy-security-slip-7000007707/
http://www.zdnet.com/password-exposed-in-click-frenzy-security-slip-7000007707/
The only potential saving grace might have been that, had they not put some serious server power behind it, more than a dozen concurrent users would make the site unusable anyway. When a project advocates clustering as a primary method of scaling (this was an official recommendation that I can't find at the moment), something is clearly wrong.
[edit] http://www.magentocommerce.com/blog/comments/performance-is-...
It's an old post, but considering the Zend-taken-to-extremes nature of the code base, I doubt the resource-intensive nature of the app has changed much. [/edit]