Topic Sponsor
Suggestions, Comments & Questions about the Forum Give us your feedback and tell us what you'd like to see or report a functionality problem.

Password reset feature is insecure

Thread Tools
 
Search this Thread
 
Old Jan 23, 2026 | 09:59 AM
  #1  
davido_'s Avatar
Thread Starter
Senior Member
Liked
Loved
Community Favorite
 
Joined: Apr 2025
Posts: 321
Likes: 244
From: Salt Lake City
Default Password reset feature is insecure

The current password reset feature emails a new password (which should be changed) in plaintext to the email address of record for an account. This allows for man in the middle sniffing of the password since email is a plaintext feature that is not guaranteed to pass entirely through TLS/SSL connections.

The safer practice is to email a reset link to the end user, and this is the practice that is typically used by most modern password-protected systems.
Reply




All times are GMT -4. The time now is 09:49 PM.