I just signed up for a site that asked for a password. Like most people, I don't create a different password for every site I visit I'd never be able to remember them.
Instead, I have a set of them, for differing levels of importance or required security. It works well, and so far I don't think I've ever had any security breaches.
The problem though is knowing which password you should use beforehand. This is a problem because some sites will email include your password in plain text in the welcome email after registration.
We all know that as soon as a password is emailed in plain text is can no longer be considered secure. These sites will no doubt also email it in plain text if you use the "Forgot Password" link too, which of course makes it worse.
I'm actually ok with this: some sites simply aren't that important and if you account gets hacked then meh. But I would like to know beforehand that they are going to be treating my password in this way before I decide which password I'm going to use.
So, New Rule: registrations should disclose if they are going to be sending the password via email in plain text prominently on the registration form itself.
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Saturday, November 22, 2008
New Rule for registration processes
Subscribe to:
Posts (Atom)