Forum Passwords in Plain Text

Give feedback and share suggestions about InkscapeForum.com.
User avatar
pilaftank
Posts: 3
Joined: Sun Sep 13, 2009 7:55 am
Location: San Carlos, California

Forum Passwords in Plain Text

Postby pilaftank » Sun Sep 13, 2009 8:23 am

97% of web users don't care about security and don't give more than a couple seconds of thought to how passwords should be handled.

Nonetheless, web sites should still have reasonable password management. This forum e-mails new account passwords in plain text. Unfortunately, e-mails have a nasty habit of never completely disappearing even after the user hits the delete key. Passwords (except for one-time temporary passwords) should never be put in e-mails (even for a low security web site like a graphic tool forum).

On the plus side, this forum's welcome e-mail message states, "Please do not forget your password as it has been encrypted in our database and we cannot retrieve it for you." That part is good.

User avatar
microUgly
Site Admin
Posts: 2985
Joined: Sat Jun 02, 2007 3:13 pm
Contact:

Re: Forum Passwords in Plain Text

Postby microUgly » Tue Sep 15, 2009 9:17 am

How do you suppose you would inform a user of their password if they can't read it?

Off topic:
Note that your account is on the verge of being deleted. Don't take it personally, but I'm not convinced you've registered on this forum just to confirm Inkscape runs on Leopard, and comment on password security. It seems more likely you are posting as an excuse to have your website linked from your signature.

You have an opportunity to convince me otherwise by demonstrating that you've created this account to participate in Inkscape discussions.

User avatar
pilaftank
Posts: 3
Joined: Sun Sep 13, 2009 7:55 am
Location: San Carlos, California

Re: Forum Passwords in Plain Text

Postby pilaftank » Tue Sep 22, 2009 9:39 am

Don't take it personally...

Wow, my criticism of this site's password management must have really struck a nerve!

How do you suppose you would inform a user of their password if they can't read it?

The user just typed it in a few seconds earlier. The user would really have to be out of it to forget his or her password in 5 seconds.

User avatar
microUgly
Site Admin
Posts: 2985
Joined: Sat Jun 02, 2007 3:13 pm
Contact:

Re: Forum Passwords in Plain Text

Postby microUgly » Mon Sep 28, 2009 8:24 pm

pilaftank wrote:
Don't take it personally...

Wow, my criticism of this site's password management must have really struck a nerve!

Nope. Any account that has a sig. and does not post about Inkscape is suspect.

The user would really have to be out of it to forget his or her password in 5 seconds.

It happens--all the time. And all major services offer password retrieval, and those passwords are always emailed. I didn't design the system this board uses, but its security system in regards to password management is nothing out of the ordinary.


Return to “Feedback & Suggestions”