my forum password sent open text in FAH welcome email

Moderator: Site Moderators

Post Reply
F5A1C
Posts: 1
Joined: Tue Nov 17, 2009 7:55 pm

my forum password sent open text in FAH welcome email

Post by F5A1C »

I just joined. The "welcome to the FAH forum" email which included my password in plain text, while assuring me that the forum doesn't know my password because it's encrypted in their database, just doesn't make sense.

Please don't send forum passwords in open text via email. :roll:

Thanks.
frvge
Posts: 1
Joined: Sun Nov 02, 2008 12:32 am

Re: my forum password sent open text in FAH welcome email

Post by frvge »

The script probably doesn't store the unencrypted password, but it receives it unencrypted from the registration form. Then it uses that in the first email and in the first email only. The encrypted password is then stored. This is normal behaviour for basically all web-software which have accounts.
Post Reply