contentblade.com contentblade.com
   Main >> About Us >> Privacy >> Terms of Service >> Place Your Link >> Add Your Article
Search:   
 
 

The Deepest Secrets To E-books

The deepest Secrets behind e-books finally revealed. If you want to know how they make it, you'll de ... - Seth Chong
 

A Look At Data Entry Jobs And The Freelancer

Data entry jobs are a nice option for anyone who enjoys typing. The basic materials that any data en ... - Peter Bishop
 

How To Find Web Hosting That Doesn??t Leave You Broke

If you have an online business or maybe even several like I do, web hosting can be a significant exp ... - Gregg Hall
 
 

Is Your Domain Name On Someone's Wanted List?

Everyday hundreds of new online businesses are looking new domain names. Find out if you have one th ... - Edwin John
 

What Certification Should You Pursue After The CCNA?

After you earn your CCNA, you've got some tough choices as to which certification to pursue next. Ch ... - Chris Bryant
 
 

Main –› Computers & Software –› Internet Firewalls & Security
 

Sending Passwords By Email

 
Author: Bryce Whitty
 

It amazes me how many sites allow you to register, and then send you an e-mail to your registered address containing your password in plain-text. There is never a warning stating that the site will email the password you use, for all to see.

Sending passwords by e-mail works when you forget a password. The site changes it and e-mails you the new one, which you then use to log in and change it to something else. The e-mailed password is not active for very long, and it isn't something you chose.

Sending you your own password, either in a welcome e-mail once you register, or as a response to a 'forgot password' request is bad security. Really bad security.

Compounding this is the fact that e-mail providers such as Google Gmail state in their privacy policy that 'deleted' e-mail may be kept indefinitely on their backup servers. As soon as someone e-mails you your password in plain-text, to a Gmail account, Google are likely to have that archived forever.

You can't tell whether a site is going to do to this, so it isn't possible to use a 'less sensitive' password for sites which will e-mail your password back to you. If you have groups of passwords; one for sites you use to pay for things, one for forums, one for other less important sites, for instance, then you may enter your 'usual' password without realising it may be compromised by being sent in an e-mail, visible to anyone along the way that wants to read it.

Sites should seriously consider the security implications of sending passwords by e-mail, especially if there is no prior warning that this will happen!

 
 
 

Related Articles

 
10 Reasons Why I'm Glad I Switched from PCs to Macs
 
How to choose your cell phone
 
How to Build a Website
 
The Best Kind Of Customer - Desperate Buyers Only
 
Is There Really Such Thing As Free Cell Phones
 
3 Reasons Why You Should Love Unsubscribes
 
Choose a Domain Name That Floods Traffic to Your Website!
 
When Search Engines Get So Complex They Backslide
 
So You Want to be a Games Developer?
 
Internet Publishing: Online Today, But What About Tomorrow Or Where Have You Gone, 406,302?
 
 
 
Add Url
 

Self Healing

Medical Care

Travel & Vacation

Online & Board Games

Business & Companies

Academics & Education

Issues & News

Politics & Government

Sports & Adventure

Automotive

Careers & Employment

Finance & Investment

Children

Science & Space

Shopping & Auction

Recreation & Entertainment

Creative Arts

Estate & Realty

Society & Issues

Computers & Software

Cooking & Drinking

Garden & Home

Lifestyle & Fashion

Health & Therapy


 
Main >> Privacy >> Terms of Service
© 2006-2008 www.contentblade.com All Rights Reserved Worldwide.