dsmythe Posted February 15, 2011 Share Posted February 15, 2011 I had a client complain that their password was send to them in the welcome email in clear text. I know I can edit the template but is this standard behavior for all password related functions such as forgot password? is this something I should worry about? thanks, -d 0 Quote Link to comment Share on other sites More sharing options...
WHMCS Support Manager WHMCS John Posted February 16, 2011 WHMCS Support Manager Share Posted February 16, 2011 Yes it is standard, no it's not something to be worries about really. The client has to be given their password somehow. 0 Quote Link to comment Share on other sites More sharing options...
AVeal Posted February 16, 2011 Share Posted February 16, 2011 I too have recently had this complaint by a user; who is an IT security specialist. He informed me that no passwords should be displayed in plaintext, via email or on screen. From this; is there a way to display a starred version of the password on the client signup email? I'll quote the extract from the correspondence with the client. "I'd definitely not want a password in any email. When you go to the effort of picking a decent strong password, I guess it seems a little counter productive having it emailed straight back to you. I appreciate your point about it being encrypted, but if that's the case - the automated system shouldn't be able to extract and send the cleartext password - it should be a one way hash." 0 Quote Link to comment Share on other sites More sharing options...
dsmythe Posted February 17, 2011 Author Share Posted February 17, 2011 I too have recently had this complaint by a user; who is an IT security specialist.He informed me that no passwords should be displayed in plaintext, via email or on screen. From this; is there a way to display a starred version of the password on the client signup email? I'll quote the extract from the correspondence with the client. "I'd definitely not want a password in any email. When you go to the effort of picking a decent strong password, I guess it seems a little counter productive having it emailed straight back to you. I appreciate your point about it being encrypted, but if that's the case - the automated system shouldn't be able to extract and send the cleartext password - it should be a one way hash." Hmm.. if they are that nuts about it.. then I think I will just remove the password from the welcome email if I can. He does have a point.. If you picked the password, then why send it back to them? if they forget then they can use the forgot password link... I guess... I don't see why people are freaking out about it... is there a global conspiracy I am not aware of? unless the email is intercepted in transit or hackers know your mailbox password... how can it be stolen? And... if it's intercepted on its way to the destination server.. do we have bigger problems? or am I huffing glue? 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.