You are not logged in.

#1 2024-12-06 08:53:41

archaur
Member
Registered: 2024-11-16
Posts: 4

Sign up

Welcome to Arch Linux Forums! by Arch Linux Forums Mailer <noreply@archlinux.org> sends passwords in plain text.

Offline

#2 2024-12-06 10:25:01

Lone_Wolf
Administrator
From: Netherlands, Europe
Registered: 2005-10-04
Posts: 13,232

Re: Sign up

Is the connection between your mail client and your mail hoster secure ?
Does the mail hoster use secure connections to communicate with other mail servers ?

If  yes, only people with access to your email client or employees of the mail hoster could potentially see it.
I expect you do trust those 2 groups ?

In case your mail client / mail hoster don't use secure connections, you are likely to have much bigger security problems then 1 password sent in plain text.


Disliking systemd intensely, but not satisfied with alternatives so focusing on taming systemd.

clean chroot building not flexible enough ?
Try clean chroot manager by graysky

Offline

#3 2024-12-06 11:03:11

WorMzy
Administrator
From: Scotland
Registered: 2010-06-16
Posts: 12,565
Website

Re: Sign up

Change the password when you first log in.


Sakura:-
Mobo: MSI MAG X570S TORPEDO MAX // Processor: AMD Ryzen 9 5950X @4.9GHz // GFX: AMD Radeon RX 5700 XT // RAM: 32GB (4x 8GB) Corsair DDR4 (@ 3000MHz) // Storage: 1x 3TB HDD, 6x 1TB SSD, 2x 120GB SSD, 1x 275GB M2 SSD

Making lemonade from lemons since 2015.

Offline

#4 2024-12-06 15:09:23

seth
Member
Registered: 2012-09-03
Posts: 60,764

Re: Sign up

If  yes, only people with access to your email client or employees of the mail hoster could potentially see it.

Does the mail hoster use secure connections to communicate with other mail servers ?

Mail is only point to point when it's encrypted. Otherwise a random amount of people have read it.

The standard procedure is a convenience thing that weighs: "How much effort is it to steal this account and how much time do you have before the legit owner changes their password" against "wtf do you do with a brand new forum account?"

It might be beneficial for the forum however if it'd require you to post a public key on registration because that forces people to setup s/mime|gpg mail and drastically raise the level of the board tongue

Offline

Board footer

Powered by FluxBB