password security

Instead of emailing or messaging the Admins or Mods with technical support questions or comments about the site, we prefer you check here to see if someone else has had the same difficulty or has made the same suggestion. What you're after might have already been posted and addressed here or within the FAQ. If not, please post a detailed description of the problem/suggestion and someone from the HST team will address your needs shortly. If you can't login/post and are unable to reset your password on your own, you may contact us directly.
Post Reply
User avatar
dbring
Topix Newbie
Posts: 3
Joined: Mon Aug 11, 2008 9:32 am
Experience: N/A

password security

Post by dbring »

I just registered and was surprised that the confirmation email showed my selected password in the clear. My understanding is that this is not a good practice from the viewpoint of web/email security.

Thanks,

Dave Ring
User avatar
ERIC
Your Humble Host & Forums Administrator
Your Humble Host & Forums Administrator
Posts: 3254
Joined: Fri Oct 28, 2005 9:13 am
Experience: Level 4 Explorer
Location: between the 916 and 661

Re: password security

Post by ERIC »

dbring wrote:I just registered and was surprised that the confirmation email showed my selected password in the clear. My understanding is that this is not a good practice from the viewpoint of web/email security.

Thanks,

Dave Ring

Hi Dave,

First of all, welcome to HST! :) - and thank you for your input. I do see some merit in your suggestion. However, the forum software we use, phpBB, is one of the most common forum softwares found on the internet. This is the first time I've heard/read this type of complaint when it comes to the phpBB forum software, and I read the comments/suggestions forum on their own Website quite often. Also, most other forum softwares out there are very similar in design to phpBB. I could be wrong, but I do believe most include this same feature.

As a suggestion; I never use the same password(s) for message forums as I use for any of my truly "sensitive" online accounts (ex. banking, Ebay, TD Ameritrade, etc). However, what's interesting is that a number of the sites I use which would fall into the "sensitive" category send passwords via email. So either those sites are being really stupid, or this practice maybe isn't as big of a cause for concern as you think it might be.

In any case, I will post your suggestion on the developer area over on the phpBB site and see if anyone has any ideas for improvement.

Thanks again,

Eric
New members, please consider giving us an intro!
Follow us on Twitter @HighSierraTopix. Use hashtags #SIERRAPHILE #GotSierra? #GotMountains?
Follow us on Facebook: https://www.facebook.com/HighSierraTopix
Post Reply

Who is online

Users browsing this forum: No registered users and 4 guests