sdesalas Posted April 16, 2021 Share Posted April 16, 2021 I just going this while trying to reset my password.Screenshot_20210416-094000720×1425 64.7 KB 7 Link to comment Share on other sites More sharing options...
angel_jasmin_5a Posted April 16, 2021 Share Posted April 16, 2021 WHY THAT ???you forget ur oldest pass? 1 Link to comment Share on other sites More sharing options...
uk1000 Posted April 16, 2021 Share Posted April 16, 2021 If they’ve done that you could contact CS to suggest they don’t maybe. But the bit you’ve put a grey mark over in the post is after the word “Hi” - so it seems like they might be showing your username there. If you used your username as the password too I wouldn’t do that. 5 Link to comment Share on other sites More sharing options...
hikarishinjo Posted April 16, 2021 Share Posted April 16, 2021 WHY THAT ???you forget ur oldest pass?When someone engages a Password Reset procedure, in general, yes, that is highly probable he might have forgotten is old password. 3 Link to comment Share on other sites More sharing options...
hikarishinjo Posted April 16, 2021 Share Posted April 16, 2021 Done it myself just for the sake of trying, and no problem encountered :image832×407 17.3 KBDo you happen to have both identical username and password ? … 4 Link to comment Share on other sites More sharing options...
sdesalas Posted April 16, 2021 Author Share Posted April 16, 2021 I have different user name and password. Yet my password appeared as the username in the email. 1 Link to comment Share on other sites More sharing options...
sdesalas Posted April 16, 2021 Author Share Posted April 16, 2021 I have different user name and password. Yet my password appeared as the username in the email.This was 6 days ago. I only had a chance to report the bug today. 2 Link to comment Share on other sites More sharing options...
uk1000 Posted April 16, 2021 Share Posted April 16, 2021 This was 6 days ago. I only had a chance to report the bug today.It might be best to report it at the helpdesk as a bug. Maybe it depends on the device you view the message in - it’s unusual that it’s not shown it on @hikarishinjo’s post but did on yours. Maybe the message source could be checked to see if it’s in there somewhere (eg. in the message source on both messages). 1 Link to comment Share on other sites More sharing options...
sdesalas Posted April 16, 2021 Author Share Posted April 16, 2021 You’re right @hikarishinjo I tried the same flow today (website + forgot password) and they sent the email correctly with my username instead of my password.Might have been they picked up the issue and already fixed it during the week.Yet the email with plain text password is still in my inbox. :man_shrugging: 2 Link to comment Share on other sites More sharing options...
sdesalas Posted April 16, 2021 Author Share Posted April 16, 2021 Having built systems like this I know they shouldnt be able to get my plain text password if they stored it as hash in the database using any of the algorithms for that purpose (SHA, HMACSHA, BCRYPT etc).So by deduction: the passwords are stored in plain text, and anyone who has access to the user database (most developers), will be able to see everybody’s passwords, not to mention the security risk if someone external gets hold of the database and publishes it. 4 Link to comment Share on other sites More sharing options...
hikarishinjo Posted April 16, 2021 Share Posted April 16, 2021 Having built systems like this I know they shouldnt be able to get my plain text password if they stored it as hash in the database using any of the algorithms for that purpose (SHA, HMACSHA, BCRYPT etc).So by deduction: the passwords are stored in plain text, and anyone who has access to the user database (most developers), will be able to see everybody’s passwords, not to mention the security risk if someone external gets hold of the database and publishes it.Hence the title of your post, now I understand. That would be indeed a very concerning issue … 4 Link to comment Share on other sites More sharing options...
sk_reza Posted April 16, 2021 Share Posted April 16, 2021 Done it myself just for the sake of trying, and no problem encountered :image832×407 17.3 KBDo you happen to have both identical username and password ? …@hikarishinjo that’s very generous of you to take that kinds of risk for experiment. 1 Link to comment Share on other sites More sharing options...
scoobydoo_1 Posted January 16, 2022 Share Posted January 16, 2022 This is still happening. They emailed me my password instead of my name. Baaaad. 1 Link to comment Share on other sites More sharing options...
Recommended Posts
Please sign in to comment
You will be able to leave a comment after signing in
Sign In Now