Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Discussion & Documentation Gentoo Forums Feedback
  • Search

clear text password on registration to the forums

Having a problem with the forums? Have a suggestion? Post here!
Post Reply
  • Print view
Advanced search
13 posts • Page 1 of 1
Author
Message
Ana-Q
n00b
n00b
Posts: 4
Joined: Wed May 17, 2023 8:27 pm

clear text password on registration to the forums

  • Quote

Post by Ana-Q » Wed May 17, 2023 9:44 pm

Hi

I registered to the forum and received an email for confirmation. Besides the link that I have to click for the confirmation, I was amazed to see in the email my username and the password. I had to change the password immediately
Please check this issue. I will be grateful to know if this bug is corrected.
Top
szatox
Advocate
Advocate
Posts: 3858
Joined: Tue Aug 27, 2013 12:35 pm

  • Quote

Post by szatox » Wed May 17, 2023 11:41 pm

It's a known issue, it won't be corrected in foreseeable future.
BTW, anyone with access to your mailbox can reset your password, so changing it immediately doesn't make a huge difference. It is admittedly a bad design, yet it doesn't seem like anyone had a much better idea so far, so we kinda live with it - and it's not limited to FGO.
Top
Hu
Administrator
Administrator
Posts: 24400
Joined: Tue Mar 06, 2007 5:38 am

  • Quote

Post by Hu » Thu May 18, 2023 12:20 am

Searching the first two pages of the feedback forum, I found the following threads discussing this:
  • Are passwords stored in plain text??
  • Gentoo Forums: On register, password is emailed in plaintext
  • New forum account creation
  • Why storing user forum password as plain text?
Top
fedeliallalinea
Administrator
Administrator
User avatar
Posts: 31985
Joined: Sat Mar 08, 2003 11:15 pm
Location: here
Contact:
Contact fedeliallalinea
Website

  • Quote

Post by fedeliallalinea » Thu May 18, 2023 5:30 am

Moved from Networking & Security to Gentoo Forums Feedback.
Questions are guaranteed in life; Answers aren't.

"Those who would give up essential liberty to purchase a little temporary safety,
deserve neither liberty nor safety."
- Ben Franklin
https://www.news.admin.ch/it/nsb?id=103968
Top
pjp
Administrator
Administrator
User avatar
Posts: 20668
Joined: Tue Apr 16, 2002 10:35 pm

Re: clear text password on registration to the forums

  • Quote

Post by pjp » Thu May 18, 2023 4:54 pm

Ana-Q wrote:I had to change the password immediately
That is the general recommendation.

As the upgrade is delayed without a set time, I wonder if some text could be changed during the signup process. This would inform users about the issue, which would hopefully be less alarming. Users would also be able to use a throwaway password rather than one they would prefer to keep.
Quis separabit? Quo animo?
Top
Chiitoo
Ninja Apprentice
Ninja Apprentice
User avatar
Posts: 3079
Joined: Sun Feb 28, 2010 5:36 pm
Location: Sore wa sore, kore wa kore... nanoda.

Re: clear text password on registration to the forums

  • Quote

Post by Chiitoo » Thu May 18, 2023 6:30 pm

pjp wrote:
Ana-Q wrote:I had to change the password immediately
That is the general recommendation.

As the upgrade is delayed without a set time, I wonder if some text could be changed during the signup process. This would inform users about the issue, which would hopefully be less alarming. Users would also be able to use a throwaway password rather than one they would prefer to keep.
That just might be a change we might dare to make... yeah.
Kindest of regardses.
Top
NeddySeagoon
Administrator
Administrator
User avatar
Posts: 56094
Joined: Sat Jul 05, 2003 9:37 am
Location: 56N 3W

  • Quote

Post by NeddySeagoon » Thu May 18, 2023 7:49 pm

Chiitoo,

In all the languages the forum supports?
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Top
pjp
Administrator
Administrator
User avatar
Posts: 20668
Joined: Tue Apr 16, 2002 10:35 pm

  • Quote

Post by pjp » Thu May 18, 2023 11:24 pm

Any that could be added would be an improvement.
Quis separabit? Quo animo?
Top
Chiitoo
Ninja Apprentice
Ninja Apprentice
User avatar
Posts: 3079
Joined: Sun Feb 28, 2010 5:36 pm
Location: Sore wa sore, kore wa kore... nanoda.

  • Quote

Post by Chiitoo » Thu May 18, 2023 11:28 pm

NeddySeagoon wrote:Chiitoo,

In all the languages the forum supports?
We can at least try that... too. :]
Kindest of regardses.
Top
sMueggli
l33t
l33t
Posts: 627
Joined: Sat Sep 03, 2022 9:22 am

  • Quote

Post by sMueggli » Wed Dec 18, 2024 2:58 pm

NeddySeagoon wrote:Chiitoo,

In all the languages the forum supports?
If the message templates are open source, why not?
Top
Hu
Administrator
Administrator
Posts: 24400
Joined: Tue Mar 06, 2007 5:38 am

  • Quote

Post by Hu » Wed Dec 18, 2024 3:51 pm

I suspect Neddy's concern was whether the author of such a change could get reasonable wording for all the target languages. This may or may not be something that machine translators can convey adequately.

On the other hand, even if only the English template were amended, that would be an improvement over the current situation. Updating all the non-English templates would be nice, but helping some users is better than helping no one.
Top
Chiitoo
Ninja Apprentice
Ninja Apprentice
User avatar
Posts: 3079
Joined: Sun Feb 28, 2010 5:36 pm
Location: Sore wa sore, kore wa kore... nanoda.

  • Quote

Post by Chiitoo » Thu Dec 19, 2024 7:35 pm

Regardless of languages, and even though the sources are available, we don't currently have any way to test any changes we make (aside from a local instance of course), update the running version, or even make any changes to the live, running version.

That is 'we' as in the forums project members.

Only the Gentoo infra members (probably only some of them) can make any changes at this time.

See also:

https://bugs.gentoo.org/431106
Kindest of regardses.
Top
Hund
Apprentice
Apprentice
User avatar
Posts: 221
Joined: Mon Jul 18, 2016 7:40 am
Location: Sweden
Contact:
Contact Hund
Website

  • Quote

Post by Hund » Sat Mar 08, 2025 9:04 am

This seems a small issue considering the fact that phpBB2 was abandoned 16 years ago. Who knows what security issues this forum comes with. :)
Collect memories, not things.
Top
Post Reply
  • Print view

13 posts • Page 1 of 1

Return to “Gentoo Forums Feedback”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic