Emailing of changed passwords

Emailing of changed passwords

Posted by: Abscissa
Posted on: 2005-02-05 08:43:00

How can I get it to *not* send my passwords though email when I change them? I'm very suprised (and dissapointed) this is turned on by default.

Re: Emailing of changed passwords

Posted by: jimspics
Posted on: 2005-02-05 13:31:00

The default is _not_ to email you a password _if_ you know what the old one was.

In the control panel, on the Password tab under Users, just leave the dot in Change Your Password. Enter your old one, then your new one twice. Click the "Change, then email password" box. (Despite the wording on the submit button, it only does what you've told it to do by putting the dot beside the option you want.)

I just did this and even entered a wrong password just to make sure email doesn't go out. If you enter a wrong one, the error does let you know that a password _can_ be emailed, but you have to request that option.

Jim


Re: Emailing of changed passwords

Posted by: Abscissa
Posted on: 2005-04-10 20:35:00

I'm still getting passwords emailed to me in certain circumstances. For instance, when I create a new ftp account and specify a password (instead of using an auto-generated one). I do not consider it acceptable for passwords to EVER be transferred in any plain-text format or even displayed on-screen - especially not by default. As a new DreamHost user I find this to be an extremely discouraging sign.

Re: Emailing of changed passwords

Posted by: nate
Posted on: 2005-04-11 11:48:00

You can have us PGP-encrypt all emails from us to you. You can set it up by clicking the "Edit Profile" link on the Web Panel:

https://panel.dreamhost.com/id/?tab=contact



nate.

Re: Emailing of changed passwords

Posted by: wjd
Posted on: 2005-04-11 11:52:00

In reply to:

You can have us PGP-encrypt all emails from us to you. You can set it up by clicking the "Edit Profile" link on the Web Panel:


OT: can you guys post your key on that page :-)

happylittlethings.com

Re: Emailing of changed passwords

Posted by: will
Posted on: 2005-04-19 19:03:00

The key is at:
http://dreamhost.com/pgp/support.asc

The key is also on public keyservers (like pgp.mit.edu) - key-ID 0x7FA461C9. I imagine a copy of the key (or a link to it) could be added pretty easily - maybe write support and suggest it.

Note, though, that encryption currently isn't supported.... only PGP-signing - so this doesn't currently address that particular problem at all.

Re: Emailing of changed passwords

Posted by: ardco
Posted on: 2005-04-19 20:15:00

And now it's here in the wiki too.

Cheers,

BobS

Tags: passwordsemaildissapointedemailingdefault