[MacPorts] #16542: Trac registration email sends password in email

MacPorts noreply at macports.org
Sun Sep 14 10:25:10 PDT 2008


#16542: Trac registration email sends password in email
--------------------------------+-------------------------------------------
 Reporter:  vpribish at gmail.com  |       Owner:  macports-tickets at lists.macosforge.org
     Type:  defect              |      Status:  new                                  
 Priority:  Normal              |   Milestone:  Website & Documentation              
Component:  ports               |     Version:  1.6.0                                
 Keywords:  security            |        Port:                                       
--------------------------------+-------------------------------------------
 When creating a new account on macports.org a registration email is sent
 containing my plaintext password.  This is embarrassingly insecure.

 I think there is a config for trac that tells it to skip sending the
 password.

 The registration screen should at least warn the user that the password
 will be mailed out.

-- 
Ticket URL: <http://trac.macports.org/ticket/16542>
MacPorts <http://www.macports.org/>
Ports system for Mac OS


More information about the macports-tickets mailing list