Title: Insecurity during Forum Registration Post by: joeytwiddle on June 03, 2011, 12:58:35 AM When I registered a new forum account, the forum sent me an email which contained my password in PLAINTEXT!
I don't think it should do that! The message was: Your registration request at Welcome to Fractal Forums has been received, joeytwiddle. The username you registered with was joeytwiddle and the password was XXXXXXXXX. Title: Re: Insecurity during Forum Registration Post by: Sockratease on June 03, 2011, 01:37:25 AM When I registered a new forum account, the forum sent me an email which contained my password in PLAINTEXT! I don't think it should do that! The message was: Your registration request at Welcome to Fractal Forums has been received, joeytwiddle. The username you registered with was joeytwiddle and the password was XXXXXXXXX. As far as I know, that part of the forum is automated and cannot be adjusted. It's no real security lapse at all though. You can, and should if concerned, change the password immediately after activating the account. The email is then worthless. Sorry it bothered you, but I think there's no way to change that. Christian (our Fearless Leader) may know for sure though :police: Title: Re: Insecurity during Forum Registration Post by: Xazo-Tak on September 06, 2011, 12:05:33 AM Do you have someone watching over your shoulder as you do emails? Is someone actually interested in stealing a brand new (and so not very valuable) forums account? I don't think so.
Title: Re: Insecurity during Forum Registration Post by: cbuchner1 on September 06, 2011, 12:24:10 AM Do you have someone watching over your shoulder as you do emails? Is someone actually interested in stealing a brand new (and so not very valuable) forums account? I don't think so. The issue is that email can be scanned easily by any third party that it is passing through (various ISPs). It's essentially like sending a postcard. And a lot of people re-use their passwords a lot, which makes it even more dangerous when such passwords get compromised. Title: Re: Insecurity during Forum Registration Post by: cKleinhuis on September 06, 2011, 01:03:53 AM ....it has been since ever since, and it stays there, i was thinkin about it, but, i came to the result that convenience superiors security :D and when you let it send to you it is also send in clear text, e.g. for password retrieval though i think smf2.x forums uses a better pw management system... but dunno about that... |