It amazes me how many sites allow you to register, and then send you an e-mail to your registered address containing your password in plain-text. There is never a warning stating that the site will email the password you use, for all to see.
Sending passwords by e-mail works when you forget a password. The site changes it and e-mails you the new one, which you then use to log in and change it to something else. The e-mailed password is not active for very long, and it isnt something you chose.
Sending you your own password, either in a welcome e-mail once you register, or as a response to a forgot password request is bad security. Really bad security.
Compounding this is the fact that e-mail providers such as Google Gmail state in their privacy policy that deleted e-mail may be kept indefinitely on their backup servers. As soon as someone e-mails you your password in plain-text, to a Gmail account, Google are likely to have that archived forever.
You cant tell whether a site is going to do to this, so it isnt possible to use a less sensitive password for sites which will e-mail your password back to you. If you have groups of passwords; one for sites you use to pay for things, one for forums, one for other less important sites, for instance, then you may enter your usual password without realising it may be compromised by being sent in an e-mail, visible to anyone along the way that wants to read it.
Sites should seriously consider the security implications of sending passwords by e-mail, especially if there is no prior warning that this will happen!
Article Source: http://www.BharatBhasha.com
Article Url: http://www.bharatbhasha.com/technology.php/42263
Article Added on Monday, May 8, 2006
| Other Articles related to "Sending Passwords By Email" by Bryce Whitty | |
On Denial of Service Attacks
I was thinking about this attack pattern after reading about the http://www.theregister.co.uk/2006/01/18/pixel_attack/ DDoSattack on the http://www.milliondollarhomepage.com/ Million Dollar Homepage. The site's owner was asked for $50,000 in exchange for the attack being halted.
It is clear, to me at least, that steps should be taken to prevent DDoS attempts at some point in the network where the bandwidth can cope. This is, usually, before it hits the destination server. Firewall hardware...
|
| Articles In LimeLight | The Embarrassing Truth About Mold
By Markus Skupeika Added on Sunday, April 20, 2008
Cushman Truckster: Small Engine Replacement Is Easy
By Ben Anton Added on Saturday, April 19, 2008
Tennis Court Lighting
By Kimberly Quang Added on Friday, April 18, 2008
The Five Cs In Credit Evaluation?
By Sam Miller Added on Saturday, April 19, 2008
Tennis Court Lighting Equipment Supplies
By Kimberly Quang Added on Friday, April 18, 2008
Buy MLM Leads? Heres How To Generate Your Own MLM Leads For Free.?
By Jason Paul Added on Saturday, April 19, 2008
Debt Negotiation Vs. Debt Management
By Carrie Reeder Added on Saturday, April 19, 2008
Plan Your Cheap Holiday To Europe
By Michael Peterson Added on Friday, April 18, 2008
We Create Our Own Reality
By CD Mohatta Added on Sunday, April 20, 2008
Understanding Credit Risk Management
By Sam Miller Added on Saturday, April 19, 2008
The Importance Of Credit Risk Management For Banking
By Sam Miller Added on Saturday, April 19, 2008
The Ins And Outs Of Ciara Harris' Relationships
By Shlomo Tommer Added on Saturday, April 19, 2008
Understanding The Nature And Benefits Of Training Scorecard
By Sam Miller Added on Friday, April 18, 2008
Automatic Or Manual Transmission For Your Vehicle
By Mark Robinson Added on Sunday, April 20, 2008
Leeds And Newcastle Great Destinations In A Car Hire
By Lakshmi Reddy Added on Friday, April 18, 2008
Time Management: 10 Top Tips For Managing Your Time Effectively
By Genevieve Dawid Added on Saturday, April 19, 2008
The Ins And Outs Of Enrique Iglesias' Relationships
By Shlomo Tommer Added on Sunday, April 20, 2008
Surface Mount Step Lights
By Kimberly Quang Added on Friday, April 18, 2008
Why Use Saddlebags Supports When Using Leather Saddlebags Or Just Get Hard Motorcycle Bags
By Dominik Hussl Added on Sunday, April 20, 2008
Making Shelves And Larger Projects For Woodworking
By Tony Scorch Added on Friday, April 18, 2008
|
| |
| About Author Bryce Whitty : |
|
Bryce Whitty owns and runs <a target="_blank" href="http://www.technibble.com">computer repair website called
<a target="_blank" href="http://www.technibble.com">Technibble.com. A website that provides technical how-tos for repairing your computer. Technibble also has many guides for getting into the
<a target="_blank" href="http://www.technibble.com">computer business or managing your existing one. We also cover other side topics such as Security and Software.
| |
|