Cleartext Passwords

Discussion forum open to any non-product specific subject regarding PROGNOSIS or Integrated Research

Cleartext Passwords

Postby beers » Fri May 28, 2010 3:17 am

How do you all feel about these forum accounts sending user passwords in clear text?
beers
 
Posts: 1
Joined: Fri May 28, 2010 3:13 am

Re: Cleartext Passwords

Postby nick » Fri May 28, 2010 3:30 am

It doesn't bother me. Maybe I'm naive, but this password has nothing to do with any of my work or personal sign ons or passwords. Someone would have to go to a lot of work to use it to break into anything else related and I don't know what they could get from it. I guess they could post something on here as me and make me look bad. I've had a long relationship with IR and I don't think anyone would believe I would do anything harmful or malicious.
nick
 
Posts: 6
Joined: Fri May 28, 2010 3:21 am

Re: Cleartext Passwords

Postby SteveDumond » Fri May 28, 2010 5:55 am

It's probably not a good idea to use clear text passwords on anything. I'm really surprised that in this day and age of encrypting everything (even internal network traffic), that this newly developed internet forum is not using some kind of encryption for the username and password.

And it's REALLY not a good idea to include the username and password in clear text in the registration Email!

Luckily this is the only site where I use this username/password.
SteveDumond
 
Posts: 1
Joined: Fri May 28, 2010 5:36 am

Re: Cleartext Passwords

Postby ericbauer » Fri Jun 11, 2010 6:59 am

You concerns are noted. We are currently exploring options to improve security across the site and will provide updates when available.
ericbauer
 
Posts: 9
Joined: Tue Feb 16, 2010 12:43 pm


Return to General Discussion

Who is online

Users browsing this forum: No registered users and 1 guest

cron