Plain Text Password in Welcome Email
November 23, 2008 11:50 PM
Subscribe
Online Security Filter: Welcome email contained plain text password. Specific examples of why this is bad needed.
I know this is a bad security practice. But why? My searching is coming up blank, so I'm turning to AskMeFi-ers.
I want to reply with documentation to the below conversation. No opinions, please; given that mine didn't really amount to much for them. :-)
(The site in question didn't ask for my cc # to sign up, but the same credentials would be used to make a purchase. At that time, a cc # is attached to the account.)
==============================
Comment: I just signed up for an account. As this is a shopping site, I used a password that I wish to remain secure. However, I just received an email thanking me for signing up. It contained my password in clear text. This type of security breach gives me concern for shopping with *****.
==============================
Thanks for the feedback Julie. I don't agree with you that this is a major security breach, but I will consider it in the next edition of our cart.
AJ
==============================
posted by TauLepton to computers & internet (19 comments total)
3 users marked this as a favorite
It's only a danger if someone somehow gets access to your email account. However if they do that you're humped nine ways from Tuesday anyway since all they have to do to your password to SomeShoppingSite.com is click the "I forgot my password" button and enter your email address have it mailed to you/them.
posted by Ookseer at 1:00 AM on November 24, 2008