Dug has a new mobile number. Please note: +44 75 15 66 16 55

« Nokia v Apple | Main | links for 2007-09-14 »

Should I be worried?

password.gif

Well, I cancelled my Quechup account two weeks ago. The interesting bit was that my gmail address book was spammed two days later. Now that is fucked up...

Anyways, I just wanted to mention that I've noticed that a bunch of services (Qloud, J!NX, thetrainline, Wordie to name a few) are sending account confirmation letters with cleartext passwords and I'm wondering if this is a growing trend?

Now I realise non ssh passwords are sort of pointless anyways (an .htaccess file is but a curtain or a screen I'm told) but still, this type of email gives sniffers access to a validated email address, your name, your alias and a chosen password. That has to be bad.

If you're gonna send email confirmations, generate a random password and get me to change it on first login ok?

  • Digg it!
  • Add to Del.Icio.Us
  • Add to Technorati
  • NewsVine
  • Furl
  • Slashdot
  • Google Bookmarks
  • Yahoo Bookmarks
  • Facebook
  • Facebook
  • Mixx
  • Add this post to Ma.gnolia

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on September 14, 2007 12:19 PM.

The previous post in this blog was Nokia v Apple.

The next post in this blog is links for 2007-09-14.

Many more can be found on the main index page or by looking through the archives.