3 ms·
I'm going to lose karma points for this but I think this issue is really mostly just paranoia. Can someone tell me what the likelihood is that someone would sn
by bfioca 19y ago
I'm going to lose karma points for this but I think this issue is really mostly just paranoia. Can someone tell me what the likelihood is that someone would sniff my password from the bits traveling in the series of tubes from the server to whatever mail service I use is? For the record, I've worked on an app that sent plaintext passwords because we thought it was useful to have a record of the password you used to register with us. We changed it pretty fast when a few disproportionately loud complaints came in, and nobody asked for it back, and I totally feel like if it makes users more comfortable that it's a good thing, but I still can't bring myself to consider plain text passwords in email a big negative. Anyone agree or am I alone? :)
- bayareaguy 19y agoIn theory, it all depends on the public value of the stuff the password is supposed to protect and the uniqueness of the password. Unfortunately the general populace frequently uses the same password for everything so if someone can get the password for their online suduku preferences, there's a chance the same password will work other places. You may not think that matters much, but you're probably doing some fraction of your users a favor by not making things worse for them.