This is exactly the sort of bug you'd expect to miss testing.

Really? If that's the case then you need to rethink your testing regime. Does the specification for the hint field contain a constraint that it must not contain the password?

