Storing session tokens in the database is a bad choice. Trying to deflect criticism by stating that other sites have been breached is a bad choice. If it was the first time some site leaked my information due to lax security maybe I would be upset, but all I will say is I'm not surprised. I'm...