This is normal? There is a major security flaw here. I just tested a registration of a user and their password is showing in the user_activation_key column. Further more, when they reset their password, the link to reset has their old password right in the URL!