CBR Forum   Classifieds   News   Photo Gallery   Search   Member List   Timeslips   Contact   Sponsors   Register   Login  

emailing users their passwords

  Printable Version
CBR >> Other >> CBR Forum Help & Suggestion Center >> emailing users their passwords Page: [1]
Login
Message << Older Topic   Newer Topic >>
emailing users their passwords - 9/30/2007 9:44:45 AM   
willpower102

 

Posts: 23
Joined: 9/30/2007
Status: offline
DO NOT, for ANY REASON, EMAIL USERS THEIR PASSWORDS.

I just check my email to find that the system had sent my password to me plain as day where someone could have read it.
Set the forum up to recover passwords by randomly generated passes that the user must change manually and NEVER EMAIL THE USERS PASSWORD!
The forum admin shouldn't even be able to see the passwords, they should be stored encrypted and checked encrypted.
Post #: 1
RE: emailing users their passwords - 9/30/2007 1:33:17 PM   
doncollins


Posts: 6230
Joined: 7/21/2005
From: OH, KY & WV
Status: offline
doncollins's photo gallery
None of us can see your password, we can change it, but we can not see the password your typed in.  If you forget your password and use the "forgot password" option, I'm assuming it will send you your password.  And it's been a couple of years since I had to create an account, but I think I remember the system sending you your login info after you create an account.  

_____________________________


(in reply to willpower102)
Post #: 2
RE: emailing users their passwords - 9/30/2007 2:17:27 PM   
doncollins


Posts: 6230
Joined: 7/21/2005
From: OH, KY & WV
Status: offline
doncollins's photo gallery
I did a test for you, when you create a new account, the system does send you an email confirming the details and in plain text, you'll see your username and password. 

_____________________________


(in reply to doncollins)
Post #: 3
RE: emailing users their passwords - 9/30/2007 2:33:06 PM   
willpower102

 

Posts: 23
Joined: 9/30/2007
Status: offline
I did assume / hope that the passwords wouldn't be archived in a way that they could be seen. (I promise, I wasn't implying any malicious intent at all)
And sorry if it sound like I was yelling. I wasn't. Just trying to REALLY stress the importance of this matter.

Emails that contain passwords in them can, i think (it's been a minute), be scanned by traffic monitors for many businesses. Some crooked techs or spying bosses look for things like that. More importantly, if someone forgets to log out of their email account, the next person can just search for "password" and bam they have it from this forum's email.

Now of course, a smart person would use a different password for forums than they would for their bank and work information. But the problem is, some ridiculously large percent of people don't take those precautions. I know it's not necessarily our responsibility to protect people from themselves, and in a way it's about as effective as p!$$!ng in the ocean, BUT it's still good practice to do our apart and cover their tracks for them.

although there are several methods, the simplest is password RESET via email instead of "recovery". (if possible adding a security question would be even better) With this method, the user who forgot their password gets a one shot email that will allow them to reset their password. OR the email could send them a temp random password, something really long like x67rDm891Wq, that would allow them one logon and instantly make them change their password.

In any of the situations the users password is NEVER displayed or sent to them, and the reset method only works once. (then they have to go through the process again if they screw it up somehow, like set themselves a pass they can't remember) And of course, they can always set the pass back to something they currently use, or even the same password it was if they end up remembering it.

edit: I forgot to mention also that it would be a good idea to take out the initial password sent on signup as well. Just the username to that they can reset if they need to.

< Message edited by willpower102 -- 9/30/2007 2:40:49 PM >

(in reply to doncollins)
Post #: 4
Login OR Register now to post a reply to this forum topic.
Page:   [1]

 
CBR Forum >> Other >> CBR Forum Help & Suggestion Center
Jump to:

Featured Sponsors
Advertising Info

Top 10 Posters
voodoochyl6548
doncollins6230
tahoe sc5842
pitsvtec5318
rrasco5128
d2dgraphix_64876
blue fox4473
vpsophmore4390
chainstretch4145
havoc4141

New Vendors
AMSOIL - Performance Oil Technology
AMSOIL - Performance Oil Technology

CBR Forum .com is not affiliated with or endorsed by Honda Motor Company.