In this case, Yahoo stored its Contributor Network usernames and passwords in plain text, which means the login credentials were immediately intelligible to anyone who broke in. Security experts say they can tell that the credentials were stored without encryption because many were too long to crack using brute-force techniques . "Yahoo failed fatally here," said Anders Nilsson , security expert and chief technology officer of Scandinavian security company Eurosecure . "It's not just one specific thing that Yahoo mishandled -- there are many different things that went wrong here. This never should have happened." Nilsson said Yahoo screwed up on three fronts: The site should have been built more robustly, so it wouldn't have been susceptible to something as simple as a SQL attack. It should have secured users' log-in information, and it should have put the equivalent of trip-wires in place to set off alarm bells when such an easily noticeable break-i...