goodygracious.com goodygracious.com
  Site Home >> About Us >> Add Your Link >> Security & Privacy >> ToS >> Add Article
Search:   
 
 

Network+ Certification Exam Tutorial: Ethernet CSMA/CD Explained

Success on the Network+ exam depends on your mastery of the fundamentals. Learn all about Ethernet C ... - 123456789
 

More Flash Tips

Pictures may tell a thousand words but sound adds that extra bit of spice. I am going to supply the ... - Matt Moyne
 

Help to choose your monitor

Making the right choice in a computer display or monitor is an important part of involving yourself ... - Andrew Gates
 
 

Being Part Of Groups

There are many different ways to have fun and socialize on the internet. One of the most fulfilling ... - Richard Lowe, Jr.
 

Does Everyone Ignore Your Newsletter?

We all know how important it is to have a successful newsletter to help market our websites. Learn h ... - Matthew Coers
 
 

Site Home › Computers & Software › Internet Firewalls & Security
 

Sending Passwords By Email

 
Author: Bryce Whitty
 

It amazes me how many sites allow you to register, and then send you an e-mail to your registered address containing your password in plain-text. There is never a warning stating that the site will email the password you use, for all to see.

Sending passwords by e-mail works when you forget a password. The site changes it and e-mails you the new one, which you then use to log in and change it to something else. The e-mailed password is not active for very long, and it isn't something you chose.

Sending you your own password, either in a welcome e-mail once you register, or as a response to a 'forgot password' request is bad security. Really bad security.

Compounding this is the fact that e-mail providers such as Google Gmail state in their privacy policy that 'deleted' e-mail may be kept indefinitely on their backup servers. As soon as someone e-mails you your password in plain-text, to a Gmail account, Google are likely to have that archived forever.

You can't tell whether a site is going to do to this, so it isn't possible to use a 'less sensitive' password for sites which will e-mail your password back to you. If you have groups of passwords; one for sites you use to pay for things, one for forums, one for other less important sites, for instance, then you may enter your 'usual' password without realising it may be compromised by being sent in an e-mail, visible to anyone along the way that wants to read it.

Sites should seriously consider the security implications of sending passwords by e-mail, especially if there is no prior warning that this will happen!

 
 
 

Related Articles

 
How to write compelling autoresponder messages to increase sales.
 
Content is NOT king
 
Top Ten Reasons To Choose A Web Hosting Provider
 
Tips and Tricks On How to Secure and Brand the Ideal Domain Name for your Business.
 
Playstation 3 Is An Entertainment Powerhouse
 
The Link Swapping Trap
 
10 Tips To Shopping For Printers
 
A Newsletter Publisher's Main Task: Packaging Value Content
 
You Need Your Own Domain Name...
 
Using Pay Per Click to Make Money
 
 
 
Add Url
 

Online Shopping

Technology & Science

Culture & Art

Recreation

News & Media

Sports

Teens & Children

Jobs & Employment

Automobiles

Self Management

Lifestyle & Fashion

Law & Politics

Banking & Finance

Healthcare & Medicine

Travel & Vacation

People & Communities

Drink & Food

Indoor Games

Property & Estate

Business & Companies

Home Family & Garden

Academics & Learning

Computers & Software

Hygiene & Health

 
Site Home >> Security & Privacy >> ToS  
Copyright © www.goodygracious.com - All Rights Reserved Worldwide.