Don't send passwords in email!

Please suggest ways we can improve this forum

Don't send passwords in email!

Postby impulse940 » Tue Dec 26, 2006 11:02 am

I registered for the forum and made an error in my email address. When I registered again with the correct one, I found that my original user name and password had been sent to my email, along with the registration verification link. I assume that my original information had been sent to the original, mistyped email, which belongs to someone else.

User names and passwords should never be sent in unencrypted email, and certainly not unless requested!
impulse940
New User
 
Posts: 2
Joined: Tue Dec 26, 2006 10:57 am

Re: Don't send passwords in email!

Postby jeff » Thu Jun 21, 2007 3:10 pm

I agree with you 100% - it's stupid to e-mail passwords, but the forum software unfortunately doesn't provide an option to turn it off. Hopefully most people don't use the same password here that they use for their bank accounts, credit card websites, etc. I guess the reason the passwords are sent is because users often forget passwords as soon as they pick them.

Also keep in mind that this forum isn't running on a secure (SSL) server, so the passwords are unencrypted. (Although I may change that soon, since SSL certs have become really cheap. Anyone want to donate money for that?)

Once the dust settles from the new release of phpBB, I'll look into modifying the board to stop sending out passwords via e-mail. Thanks for the suggestion!
User avatar
jeff
Site Admin
Site Admin
 
Posts: 338
Joined: Fri Aug 23, 2002 12:42 pm
Location: Houston, TX


Return to Suggestion Box

Who is online

Users browsing this forum: No registered users and 1 guest