by janer » Mon Jun 06, 2011 6:10 am
Hello,
I have just received the following criticism from a newly-registered reader:
"For security reasons it is most inappropriate to send passwords in plain text by email. Many users take the same password for several registrations, as ones memory for such things is not infinite.
At least you ought to explain on your website that you are going to confirm the password by email and warn the prospective users to use a new password that is not used in any other context."
I tried to track down any previous correspondence in the Forum but could not, and when I looked to see if I could edit the automatically-generated registration email to suggest to the recipient that they change their password immediately to something more memorable to them, it isn't in the list of prepared emails available to me as Journal Manager and anyway it would presumably result in yet another email containing the new password. I think the suggestion of warning the user is a good one however, and would like to be able to do that on the registration template, but don't know how to.
The system seems to have been designed around sending confirmation emails with the username and password in full - isn't that rather risky nowadays?
Best wishes,
Jane