Advertisement
Help Keep Boards Alive. Support us by going ad free today. See here: https://subscriptions.boards.ie/.
If we do not hit our goal we will be forced to close the site.

Current status: https://keepboardsalive.com/

Annual subs are best for most impact. If you are still undecided on going Ad Free - you can also donate using the Paypal Donate option. All contribution helps. Thank you.
https://www.boards.ie/group/1878-subscribers-forum

Private Group for paid up members of Boards.ie. Join the club.

Passwords over email

  • 08-08-2013 11:18AM
    #1
    Registered Users, Registered Users 2 Posts: 37,485 ✭✭✭✭


    It really bugs me when you sign up to something and get sent the password by email. That password is now compromised (IMO anyway).

    I just signed up to the OWASP Ireland mailing list and they sent me the password I used to sign up. Don't do that! A security mailing list that emails me my password in plaintext? COME ON PEOPLE!

    For people (not me, thankfully) who reuse the same password over and over it could lead to a very bad time.

    Rant over.


Comments

  • Registered Users, Registered Users 2 Posts: 2,626 ✭✭✭timmywex


    Khannie wrote: »
    It really bugs me when you sign up to something and get sent the password by email. That password is now compromised (IMO anyway).

    I just signed up to the OWASP Ireland mailing list and they sent me the password I used to sign up. Don't do that! A security mailing list that emails me my password in plaintext? COME ON PEOPLE!

    For people (not me, thankfully) who reuse the same password over and over it could lead to a very bad time.

    Rant over.

    Id forgot OWASP do that...very poor really


  • Closed Accounts Posts: 587 ✭✭✭Dum_Dum


    Mailman list passwords are not strictly required and are regarded as 'throwaway'.


  • Registered Users, Registered Users 2 Posts: 1,298 ✭✭✭moc moc a moc


    Don't forget that this probably means that they are also storing passwords in plaintext! You should bring this to their attention directly - particularly shameful given the 'security' prentences of the OWASP folks.

    With all the high-profile password DB hacks we've had in recent years, you'd think people would learn...


Advertisement