I called customer service of a well known company and discovered that the operator had the ability to view my website password in clear text on her screen.
I asked her about this and she defended the policy saying it was for FCC (Federal Communications Commission in the USA) compliance.
I've never heard of this requirement, and would love to know if any industry is required to keep a clear text version of the password, or if the IT manager responsible for this is referenced in this popular SO question.
Is there any legitimacy to the representatives claim that a clear-text password is required by law?
Update 1:
I called the manager for more information. Their reasoning for knowing the cleartext password is related to "CPNI", or Customer Proprietary Network Information. I will need to research this topic more.