3 ms·
Obviously no company should be storing passwords in a way that the password can be determined from storage. But the one (unlikely) case where these emails woul
by kag0 5y ago
Obviously no company should be storing passwords in a way that the password can be determined from storage.
But the one (unlikely) case where these emails would be permissible is in first time account creation, where the user didn't set their password when the account was created (maybe it was created by an admin). If a one time (hopefully expiring) password is generated, stored securely, and simultaneously sent to the user then some of these are acceptable.
- ThePowerOfFuet 5y agoWhy? Just make the user go through the reset-password flow.
- premek 5y agoin that case you don't send them a randomly generated string called a password but a randomly generated string called a token, right?
- ThePowerOfFuet 5y agoCorrect, but it's generated only when they initiate the reset-password flow, and should be time-limited and only usable once. It's not stored in the database for long periods.