If this is your first visit, be sure to
check out the FAQ. You will have to register
before you can post. To start viewing messages,
select the forum that you want to visit from the selection below.
Please do not use the CODE tag when pasting content that contains formatting (colored, bold, underline, italic, etc).
The CODE tag displays all content as plain text, including the formatting tags, making it difficult to read.
I just registered with this forum and was surprised to see my password in plain text in the activation email. Please don't include any password in activation email for security reasons.
Thanks.
Re: Please do not show password in activation email.
Originally posted by RealG187
I don't think they can do that. There might be a setting, but the email is send out automatically by a computer.
I know that activation emails are sent automatically by a computer. What I suggest is to disable the the setting (if any) for including passwords in emails. Displaying passwords in plain text is not a good practice.
Re: Please do not show password in activation email.
This forum does not use SSL. You should not use a password that is important to you because when you do you are sending it across the network in plain text every time you login to the forum. That is much more of a security problem than it being sent once in an email. If you are using a password for this forum and other insecure URL's that you also use for secure logins you are asking to get cracked.
Re: Please do not show password in activation email.
Originally posted by mando_hacker
. . . you are sending it across the network in plain text every time you login to the forum. That is much more of a security problem than it being sent once in an email.
Your reasoning is that we should not care because the problem is even worse than we thought. Is that it?
As far as forum accounts being hacked, that would be a bigger problem for the admin than for the users. Sure, we may lose our identities and posts in this forum, but the admin would be left with a useless, empty forum. That would be a shame for all of us.
Re: Please do not show password in activation email.
I think mando hacker is pretty correct on this. He's not saying we should not care because the problem is worse, he's saying it's only a problem if you're using the same password for this forum as you're using for your online banking or credit card access (or porn account or whatever ). I think he's right.
There is nothing to hack or steal on this forum, or there shouldn't be if you've kept private information off of it. So, with nothing at risk, who cares what the password is?
Remember, our host is an uncompensated volunteer -- he can't be expected to assume personal responsibility for forum users' security.
Re: Please do not show password in activation email.
Originally posted by Telengard
There are already hacked accounts and the pornspam appears to be proliferating quite rapidly.
Like all open, public Internet forums, this one has been a periodic target of spammers for years. Since any user name that was not previously registered can open an account, there is no practical way to prevent the abuse in advance. That's why we have moderators with the power to close accounts that violate the rules of use.
Again, this is totally irrelevant to the means by which user passwords are transmitted to users. There's nothing here to hack, except the information that a user has chosen to show.
Re: Please do not show password in activation email.
Originally posted by dibl
Originally posted by Telengard
There are already hacked accounts and the pornspam appears to be proliferating quite rapidly.
Like all open, public Internet forums, this one has been a periodic target of spammers for years. Since any user name that was not previously registered can open an account, there is no practical way to prevent the abuse in advance. That's why we have moderators with the power to close accounts that violate the rules of use.
Again, this is totally irrelevant to the means by which user passwords are transmitted to users. There's nothing here to hack, except the information that a user has chosen to show.
Yeah, I got a little angry when I saw it happening. So I overreacted and jumped to conclusions. Sorry for dragging the thread off topic. Thanks dibl.
Comment