4 ms·
That isn't the point, if they can send it in plaintext then they have it in a recoverable form. They shouldn't be storing your password at all. They should be
by sp8 12y ago
That isn't the point, if they can send it in plaintext then they have it in a recoverable form. They shouldn't be storing your password at all. They should be storing a hash of your password.
And on top of all that, sending it plaintext via email, itself a largely open format, means they've broadcast it to all kinds of other potentially bad actors.
Plus it indicates (to me) a questionable grasp of security, not a great sign for a VPN provider.
Its just wrong.
- Karunamon 12y agoIt could very well just mean that the email is sent before any hashing occurs (as part of the registration controller, in other words) - but yeah, you're right, considering that email's physical equivalent is a postcard, it shows a tremendous lack of respect for the user. Kiss of death for a supposedly privacy focused operation like a VPN provider.