4 ms·
I would take it a step further. Why email plain text passwords? It usually stays in your inbox. This increase the chance of someone being able to get your passw
by datums 17y ago
I would take it a step further. Why email plain text passwords? It usually stays in your inbox. This increase the chance of someone being able to get your password. It now exists on your laptop/desktop and on a email server, depending on your settings. There should be a reset password, but not a recover password. Send a link to a secure page which asks for something the user knows/has username ?
- cturner 17y agoApple dev site does this.
- ErrantX 17y agoSo many sites email your initial registration details to you in plain text. Even if they store them hashed up in future it's just a bad bad idea :( I know my damn password - I just typed it in :)
- rythie 17y agoI know, it's really annoying MySpace do this
- tptacek 17y ago99% of the time, if you own the mail spool behind an account on a web application, you own the account, because of password reset.
- cperciva 17y agoYes, but with password reset you don't also own every other account the user has where they reused the same password.
- tptacek 17y agoAnd? That has nothing to do with my point. I'm saying "the step forward" proposed upthread isn't one.
- m_eiman 17y agoYou kind of do, since you can reset pretty much every password using email.
- cperciva 17y agoOnly the ones which have password reset mechanisms. My bank doesn't, for example, because they realize that intercepting someone's email shouldn't allow an attacker to get access to the victim's bank accounts -- but that wouldn't help me if I used the same password for my bank as I did for 37signals.
- tetha 17y agoI think the point kind of is: If the plain text password (which is reused on multiple sites) is sent out via email, then you need to compromise a single email in order to compromise many accounts. If you want to abuse pasword-resetting mechanisms from N sites, you have to compromise N emails. This means: mailing the password in plaintext might result in a lucky attacker seeing the password over your shoulder and then, he has access to a lot of stuff. If he just sees a password reset link, he has seen nothing. Of course, this includes compromising the account, because once the account is compromised, an arbitrary amount of emails is compromised (and thus, of course, also 1 email and N emails).