Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

ScottyTheMenace

macrumors member
Original poster
Apr 5, 2013
37
2
I was just horrified to realize that you guys send plain text passwords via email on a reset. Please tell me you have imminent plans to fix this serious lack of security.
 
Since this is only a temporary password and the email encourages you to modify the password, which you just have done, the only harm should be from people directly having access to your mail account, or not?

Anyway, many sites that give out temporary passwords do that plain text blasphemy.
 
I was just horrified to realize that you guys send plain text passwords via email on a reset. Please tell me you have imminent plans to fix this serious lack of security.

Unfortunately, it's how our software works at the moment. You are recommended to change your password when you go through the recovery process.

Note, you can't ever retrieve your current password in plaintext.

arn
 
Unfortunately, it's how our software works at the moment. You are recommended to change your password when you go through the recovery process.

Note, you can't ever retrieve your current password in plaintext.

arn

I've had one website send me my own password in plain text after activating an eBook. This is over a year after I made the account, and I never requested a password be sent. "Congrats, you now own this eBook [account]: [password]"

I still shutter thinking about where it is probably stored...
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.