View previous topic :: View next topic |
Author |
Message |
fulalas n00b
Joined: 21 Feb 2022 Posts: 2
|
Posted: Mon Feb 21, 2022 2:13 am Post subject: Why storing user forum password as plain text? |
|
|
Today I created an user account here and I received an email with a link to validate the new account, however in this same email I can see my password in plain text. Isn't it a security risk? |
|
Back to top |
|
|
sam_ Developer
Joined: 14 Aug 2020 Posts: 2038
|
Posted: Mon Feb 21, 2022 3:40 am Post subject: |
|
|
There are plans in motion to migrate to phpBB3 which will solve this issue.
(Note that emailing in plain text at the point of registration isn't the same as storing in plain text though.) |
|
Back to top |
|
|
fedeliallalinea Administrator
Joined: 08 Mar 2003 Posts: 31351 Location: here
|
Posted: Mon Feb 21, 2022 6:06 am Post subject: |
|
|
Moved from Other Things Gentoo to Gentoo Forums Feedback. _________________ Questions are guaranteed in life; Answers aren't. |
|
Back to top |
|
|
xaviermiller Bodhisattva
Joined: 23 Jul 2004 Posts: 8722 Location: ~Brussels - Belgique
|
Posted: Mon Feb 21, 2022 8:34 am Post subject: |
|
|
Hi,
The passwords are not stored in clear text. The only place it is displayed clear is in the welcome mail.
See Bug 431106 _________________ Kind regards,
Xavier Miller |
|
Back to top |
|
|
NeddySeagoon Administrator
Joined: 05 Jul 2003 Posts: 54640 Location: 56N 3W
|
Posted: Mon Feb 21, 2022 9:36 am Post subject: |
|
|
... and only at first registration.
It does not happen if you change your password. _________________ Regards,
NeddySeagoon
Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail. |
|
Back to top |
|
|
|