Kayako logo
Now Implemented (V4) Feature requests that have been implemented.

Closed Thread
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  (#1) Old
jrp2 Offline
New Member
 
Posts: 5
Join Date: Apr 2008
Lost password email should not have real password in email - 01-05-2008, 03:02 PM

Overall I am super-pleased with Kayako, but this policy of sending the actual password in the lost password email is generally considered bad form. Many people use the same password for many applications, and this ends up sending that password in a clear text email.

Most "lost password" schemes involve setting a randomly generated password and mailing that to the customer. They can then log back in and change their password to whatever they want. Some go further by sending a one-time token. That is probably best, but perhaps overkill.

It would seem relatively trivial to do. The code to set random passwords already exists. It would just involve invoking that code before sending the lost password email.

Just my thoughts. Keep up the good work, Kayako is a really nice application!

JP

PS. Yes, of course I have disabled sending the password in ticket emails! I am glad that was configurable!
   
  (#2) Old
Jamie Edwards Offline
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,420
Join Date: Jan 2006
Location: United Kingdom
18-08-2008, 09:29 PM

In Version 4, plain text passwords will not exist.


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
   
Closed Thread

Tags
lost, password, real

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Sending users password in reply email Xoopiter-Craig SupportSuite, eSupport and LiveResponse 6 24-01-2007 02:36 PM
email rejected, get lost? HollyRidge SupportSuite, eSupport and LiveResponse 2 19-10-2006 03:41 PM
Disable Lost Password karmedic SupportSuite, eSupport and LiveResponse 4 10-04-2006 07:40 PM



Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46