Korg Forums Forum Index Korg Forums
A forum for Korg product users and musicians around the world.
Moderated Independently.
Owned by Irish Acts Recording Studio & hosted by KORG USA
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Plaintext Password sent by Mail after Registration

 
Post new topic   Reply to topic    Korg Forums Forum Index -> Testing This Forum
View previous topic :: View next topic  
Author Message
miazma



Joined: 29 May 2019
Posts: 2

PostPosted: Wed May 29, 2019 10:29 am    Post subject: Plaintext Password sent by Mail after Registration Reply with quote

Hi

I just registered to this forum and was a bit stunned when I received an Email asking for activation by email verfication, which also contained username and password in plain text.

IMHO the password should be put directly into the database with proper encryption and never ever go anywhere else. This has been common sense for almost decades.

In this case, this plain text password is now stored on many many servers (mail servers for example), as mails are might sometimes be sent using encrypted channels, but in this case are for sure not encrypted themselves.

I would strongly suggest changing this behavior Wink
Back to top
View user's profile Send private message Visit poster's website
karmathanever
Platinum Member


Joined: 12 Jan 2004
Posts: 8684
Location: Australia (Oz !!)

PostPosted: Thu Jun 06, 2019 1:14 pm    Post subject: Reply with quote

Once confirmed as a member you can change your password as many times as you wish.
If of course you use the same password for other login purposes (e.g. mail, banking etc..) then that is dangerous and I recommend you change that practice immediately.

Receiving "text" login confirmations is common practice for these types of public forum.

If you ever find or think that someone may be using your forum login, change your password and also PLEASE let us know.

The security on these forums (login/password) is designed to enable you to publicly post comments, questions and support.

Like in most public forums, there is not a high security risk. Administration access is of course more critical.

If someone did manage to track your initial password there is little they could do with it other than perhaps post annoying texts - you have complete control of that.

So if you are still worried, please change your password now and all will be fine.

Cheers

Pete Very Happy
_________________
------------------------------------------------------------------
Korg:--- PA4X-76, Kronos-61, WaveDrum Global
Roland:---- Integra-7
Premier:--- Mid 90's Genista
------------------------------------------------------------------
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Korg Forums Forum Index -> Testing This Forum All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group