Please don't send username/password in confirmation email.
Sending our password in the forum sign up confirmation is a very bad idea. Email travels un-encrypted and bounces off of many random servers until it finds its destination. Anyone along the way who happens to be listening could potentially grab the password.
Apr 6th, '08, 21:55
Posts: 20891
Joined: Apr 22nd, '06, 20:52
Scrolling: scrolling
Location: Back in the TeaCave atop Mt. Fuji
Re: Please don't send username/password in confirmation emai
As true as your comment may be, it is soooo commonly done. I mean it is the norm, everyone does it when you sign for virtually anything.pirripb wrote:Sending our password in the forum sign up confirmation is a very bad idea. Email travels un-encrypted and bounces off of many random servers until it finds its destination. Anyone along the way who happens to be listening could potentially grab the password.
One solution is to sign up with a secondary password...then edit it later which would not be emailed.
blah blah blah SENCHA blah blah blah!!!
Well, that's good practice, but it shouldn't be necessary. Besides, what's to say that they won't email your password whenever you change it.
Emailing a password is simply something you should never do; that's all there is to it.
I'm not so sure it's common either. At least, I can't ever remember seeing it done before.
Emailing a password is simply something you should never do; that's all there is to it.
I'm not so sure it's common either. At least, I can't ever remember seeing it done before.
Apr 6th, '08, 22:39
Posts: 1559
Joined: Jan 28th, '07, 02:24
Location: Fort Worth, TX
Contact:
Space Samurai
Apr 6th, '08, 22:40
Posts: 20891
Joined: Apr 22nd, '06, 20:52
Scrolling: scrolling
Location: Back in the TeaCave atop Mt. Fuji
I see it done constantly...register on most sites who send confirmation emails...it shows your user name and password.pirripb wrote:Well, that's good practice, but it shouldn't be necessary. Besides, what's to say that they won't email your password whenever you change it.
Emailing a password is simply something you should never do; that's all there is to it.
I'm not so sure it's common either. At least, I can't ever remember seeing it done before.
blah blah blah SENCHA blah blah blah!!!
Apr 6th, '08, 22:41
Posts: 20891
Joined: Apr 22nd, '06, 20:52
Scrolling: scrolling
Location: Back in the TeaCave atop Mt. Fuji
Space Samurai wrote:I totally know what you mean. This one time, someone got my password, then they logged on and started talking about tea that I would never drink, lavendar and chamomile and what not. It was horrible. To this day people still think I shopt at Republic of Tea. Its so humiliating.

I will see if we can set the password to automatic default using the user name as temp password...and instructing new member to change it promptly.
It is a good point, no argument there at all.
Apr 7th, '08, 00:58
Posts: 1598
Joined: Jan 11th, '07, 16:13
Scrolling: scrolling
Location: SF Bay Area, CA
Contact:
scruffmcgruff
I agree; it really shouldn't be necessary. As to Space's comment, sure, nobody really cares about what is said on this forum, but someone could use that password on other more important accounts (bank, paypal, etc.), assuming the person uses one password (which many of us do), and do some serious damage. Of course, it's a longshot, but it happens enough to be a legitimate concern, IMO.pirripb wrote:Well, that's good practice, but it shouldn't be necessary. Besides, what's to say that they won't email your password whenever you change it.
Emailing a password is simply something you should never do; that's all there is to it.
I actually have seen this quite a few times. Still, that doesn't make it a good practice, just a common one.pirripb wrote:I'm not so sure it's common either. At least, I can't ever remember seeing it done before.
Tea Nerd - www.teanerd.com
Apr 7th, '08, 01:05
Posts: 1559
Joined: Jan 28th, '07, 02:24
Location: Fort Worth, TX
Contact:
Space Samurai
Fair enough.scruffmcgruff wrote: I agree; it really shouldn't be necessary. As to Space's comment, sure, nobody really cares about what is said on this forum, but someone could use that password on other more important accounts (bank, paypal, etc.), assuming the person uses one password (which many of us do), and do some serious damage. Of course, it's a longshot, but it happens enough to be a legitimate concern, IMO.
Apr 7th, '08, 01:19
Posts: 20891
Joined: Apr 22nd, '06, 20:52
Scrolling: scrolling
Location: Back in the TeaCave atop Mt. Fuji
While I do see passwords sent in plain text a lot, that doesn't mean it's the best practice.
Encryption and what-not aside, if I open the e-mail and my password is in plain view, someone looking over my shoulder could see.
I'm okay with my password being sent if I personally request it. But when I register, it is very annoying. I know what my password was, I just typed it!
Encryption and what-not aside, if I open the e-mail and my password is in plain view, someone looking over my shoulder could see.
I'm okay with my password being sent if I personally request it. But when I register, it is very annoying. I know what my password was, I just typed it!
Apr 7th, '08, 11:49
Posts: 1598
Joined: Jan 11th, '07, 16:13
Scrolling: scrolling
Location: SF Bay Area, CA
Contact:
scruffmcgruff
Try reading the rest of the thread before you respond to the original poster; these issues have already been addressed.jazz88 wrote:I wouldn't be concerned because: a) there is no personal information b) no $$ involved. Just change your password – end of story.
Tea Nerd - www.teanerd.com
Apr 7th, '08, 20:23
Posts: 1598
Joined: Jan 11th, '07, 16:13
Scrolling: scrolling
Location: SF Bay Area, CA
Contact:
scruffmcgruff
Indeed, as was yours. You were dismissive of a reasonable concern, so I was dismissive of your comment.
Tea Nerd - www.teanerd.com