Page 1 of 1

Plaintext password in activation e-mail...

Posted: 04 Dec 2007 18:23
by robot_army
passwords should not be sent in plaintext ever, but they're sent out with the account name in the activation e-mail... that's hardcore not secure, don't you think?

Re: Plaintext password in activation e-mail...

Posted: 05 Dec 2007 05:14
by Jean-Baptiste Kempf
For the forum ? Really ?
Ask the phpBB team.

Re: Plaintext password in activation e-mail...

Posted: 30 Jun 2008 12:04
by samsmartguy
I do not agree with you, I think it is quite OK to send password in email letter.

Re: Plaintext password in activation e-mail...

Posted: 10 Jul 2008 13:46
by javad583
Look , my answer is related to web programming just a bit. In Registration progress, when the engine gots your wanted information such as : user name - password - email address and more, it will begin 2 process. at first it makes an MD5 copy of your desired password and insert it to database, then it set a plain text copy of that to your mail box using mail() function. So your passwords are still secure unless there is any problem due to your mail account security.

Tips ::
1- if you pay attention you will find out that on retrieving password using "Remember password" in (PHPBB), it makes a new copy of password for you randomly, if it was plain text in database there was no need to make a new one !
2- if there is a problem in your mail box there is nothing safe for you , ANYONE can hack you through this link :: ucp.php?mode=sendpassword
3- this is just first my post , congratulation ... :lol:

Re: Plaintext password in activation e-mail...

Posted: 25 Aug 2009 16:20
by kirdie
I was just at my universities computer pool and I was very surprised that my registration mail contained the password - my neighbours or people behind me could have seen it without a problem. In my opinion this is really unsecure.

Re: Plaintext password in activation e-mail...

Posted: 25 Aug 2009 17:00
by 3breadt
That's how most boards and other sites where you have to register do it, you should be aware about that and never read emails concerning registrations in a public place.