Forum registration itself violates security
Posted: Sun Aug 02, 2009 1:42 pm
I like NoScript. I've been using it for a while (2 yrs-ish). I trust you people.
Thus, I was shocked to see that my user name and password used on the forum registration was sent back in clear text as part of my activation email. This is very bad. Please correct this, either by stopping such practice, or (at least) warning the registrant that their info can easily be sniffed (thus they could / should use an initial password that they can change immediately after registration is activated).
Even though I used a generic "for web account management only" email and connected to it via a secure HTTPS channel, unless your outbound email is secure (and the intermediate email service is not compromised) my information is at risk. Fortunately, I used a "low security" username and password (easy for me to remember, reused on many sites, not a major concern if such credentials leak). Never the less, I don't like the vulnerability and - more importantly - other forum registrants might could easily be at more risk.
Please fix this.
Thus, I was shocked to see that my user name and password used on the forum registration was sent back in clear text as part of my activation email. This is very bad. Please correct this, either by stopping such practice, or (at least) warning the registrant that their info can easily be sniffed (thus they could / should use an initial password that they can change immediately after registration is activated).
Even though I used a generic "for web account management only" email and connected to it via a secure HTTPS channel, unless your outbound email is secure (and the intermediate email service is not compromised) my information is at risk. Fortunately, I used a "low security" username and password (easy for me to remember, reused on many sites, not a major concern if such credentials leak). Never the less, I don't like the vulnerability and - more importantly - other forum registrants might could easily be at more risk.
Please fix this.