workload: prevalence of encrypted passwords myth: noone silly enough to use unencrypted passwords anymore data: most unencrypted passwords are from one source: POP why aren't folks using APOP? (authentication already provided) mere existence of an encryption technology is no guarantee of its adoption