Page 1 of 1

Sending passwords in emails is unsecure.

Posted: 16.08.2005, 16:40
by Petya
Hello Guys,

Have anybody noticed that this kind of forum code sends out your password back to you when you register ?
I personally hate this. I already don't know how many forums and sites I'm registered in, but certainly above 100. It is impossible to remember different login information for each site. So I have a regular one and use it as widely as possible. But this behaviour ruins the logic, because it's very easy for someone to catch the password, so it's highly unsecure.

I assume that it's common sense not to send passwords in e-mails.

Am I right ?

Peter


***** BLOCK START *****
Welcome to ZEOS Library - Forum - Forums

Please keep this email for your records. Your account information is as follows:

----------------------------
Username: Petya
Password: ***************** <- password was written here
----------------------------

Your account is currently inactive. You cannot use it until you visit the following link:
***** BLOCK END *****

Re: Sending passwords in emails is unsecure.

Posted: 23.08.2005, 18:24
by AVee
Petya wrote:Hello Guys,
I already don't know how many forums and sites I'm registered in, but certainly above 100. It is impossible to remember different login information for each site.
Wich is exactly why i'm happy the password is emailed to me :)
So I have a regular one and use it as widely as possible. But this behaviour ruins the logic, because it's very easy for someone to catch the password, so it's highly unsecure.
Having the same password everywhere is just as insecure. It's all a matter of security vs. convenience, personally i don't believe anybody will be that interested in hijacking my account on this forum. Sniffing email still requires quite some work...