This forum has been archived. All content is frozen. Please use KDE Discuss instead.

The forum is sending the password in clear text in the welcome mail...

Tags: None
(comma "," separated)
Loibisch
Registered Member
Posts
6
Karma
0
This has less to do with Amarok and more to do with these Forums.

I was pretty surprised (read: shocked) to see my forum password in clear-text in the welcome E-Mail. Seriously, that's a big no-no and you should stop doing that.
Loibisch
Registered Member
Posts
6
Karma
0
Ah, and while we're at it:
I've chosen not to have my email address displayed to the public, and yet I still see an "email" icon right next to my posts, which has a plain mailto: link with my address in clear-text...ready for any spambot to harvest the address. Are you guys serious?
User avatar
dangle_wtf
Moderator
Posts
1252
Karma
0
No one's forcing you to stay, honey.


"There are two theories to arguing with women. Neither one works."
.
If men could get pregnant, we'd learn the true meaning of "screaming nancyboy wuss"
User avatar
Alanceil
Registered Member
Posts
160
Karma
0
OS
Loibisch wrote:Ah, and while we're at it:
I've chosen not to have my email address displayed to the public, and yet I still see an "email" icon right next to my posts, which has a plain mailto: link with my address in clear-text...ready for any spambot to harvest the address. Are you guys serious?


And only you can see it, I see only the PM and Profile button.
@Password: I agree with you there, the password shouldn't be sent out with the welcome mail. However, I don't know if you can disable this in a Simple Machines Forum.
Loibisch
Registered Member
Posts
6
Karma
0
Alanceil wrote:And only you can see it, I see only the PM and Profile button.
@Password: I agree with you there, the password shouldn't be sent out with the welcome mail. However, I don't know if you can disable this in a Simple Machines Forum.


Ok, that's pretty weird, that I can see my own email button but other people can't. Didn't quite expect that.
As for the password sending, that should be very easy to located in the code. Just comment out the part in the outgoing email that includes the password...there, done.

@funny mod:
While indeed noone is "forcing me to stay", may I point out to you that the damage is already done?
User avatar
dangle_wtf
Moderator
Posts
1252
Karma
0
Damage is only already done if you foolishly used a password that is not unique to this board.
Not really trying to defend the settings, just pointing out that sometimes people need to be proactive about their own security.
Did you not change your password once your registration was complete? That's fairly standard operating procedure...


"There are two theories to arguing with women. Neither one works."
.
If men could get pregnant, we'd learn the true meaning of "screaming nancyboy wuss"
Loibisch
Registered Member
Posts
6
Karma
0
Actually "changing your password once you've registered at a board" is only necessary if they've foolishly sent you the password in plaintext. And that's far from "standard procedure".

I generally use low-security passwords for boards. But seriously, change that setting.


Bookmarks



Who is online

Registered users: Bing [Bot], Google [Bot]