| E-mailing of passwords Posted: 4/10/2006 1:24:04 PM | I have messaged the admins directly about this (many weeks ago) via the "help" page, but apparently they don't read that, so I'm hoping they read these forums.
My problem, and I consider it a big one, is that this site automatically sends out passwords by e-mail in plain-text to people who have not asked for them! This is a serious security risk, and there is a reason why no other site on the web does it. (In fact the sites with really good security don't even store your password, just a hash of it - if you lose it they make up a new one for you)
Please fix this very glaring and simple issue. | |
|
RuMoR
| Joined: 1/20/2006 Msg: 2 | |
| E-mailing of passwords Posted: 4/10/2006 1:50:06 PM | Well...
I'm not sure about the whole geek thing...
But I do agree that this is a serious enough issue that unless I have asked for my password to be sent to me or changed, I shouldn't have to say "excuse me can you turn your cheek while I check my email... You just never know when someone is going to email YOU YOUR password..." not FN likely!
Excuse my "FN" language, but I not only want certain people to know I visit this site, I certainly don't need them checking out my favorites, or inbox... or that sort of nature. If they want to visit this site, they can get their own login/pass. They shouldn't have such easy access to mine. | |
|
| E-mailing of passwords Posted: 4/10/2006 1:54:42 PM | Only one person has access to such info: the Admin/site owner.
You can change your own password:
Sign into mail/edit profile/Edit More Registration Details like passwords HERE | |
|
| E-mailing of passwords Posted: 4/10/2006 2:23:22 PM | Even the site owner should not have access to it, but that is beside the point.
And changing my password would be useless, it would just be e-mailed again the next week, which is the problem: Like RuMoR says, I shouldn't have to worry about who is behind me (or even just on the same network) when I get my e-mail. | |
|
| E-mailing of passwords Posted: 4/10/2006 2:27:10 PM | | jeeezzz.... it is a dating site password.... not your bank acct... so not a big deal... | |
|
| E-mailing of passwords Posted: 4/10/2006 2:29:44 PM | | All sites that are user accessed email passwords. I don't get it, they HAVE to email it to you, if you're getting it at work and it's viewed on your company's internal network, that's not something the site can control. Don't you own a home PC? Sounds like your problem is that you're getting personal email at work. Hope you still have your job!! | |
|
| E-mailing of passwords Posted: 4/10/2006 2:38:37 PM | I've changed my password several times and not been mailed.......ever.
If you forgot your password and requested it....how else are they going to send it to you? Hand delivered telegram from a Brinks agent?
Even the site owner should not have access to it A necessity. He needs to be able to review complaints about harrassment via email. Having a life and nearly single-handedly running a site with over a million users....I doubt if he has time or desire to see what "johnny" wrote "susie". | |
|
| E-mailing of passwords Posted: 4/10/2006 2:47:54 PM | Hate to break the news, sparky, but I run a message board myself and I have access to all the passwords if I needed them for some reason. I'm sure most sites are the same. EDIT: Correction, the board controls that. I was thinking of IP addies. | |
|
| E-mailing of passwords Posted: 4/10/2006 3:01:39 PM |
I've changed my password several times and not been mailed.......ever. My password is emailed to me every single week. When they send you that weekly email saying here are your new matches and your user name and password. I don't like that either. | |
|
| E-mailing of passwords Posted: 4/10/2006 3:18:49 PM |
jeeezzz.... it is a dating site password.... not your bank acct... so not a big deal...
I strongly disagree. Any site that has a password shouldn't fling it around the 'net at random.
All sites that are user accessed email passwords. I don't get it, they HAVE to email it to you
Wrong. Not all do, and none but this one do it Without Being Asked To!
I've changed my password several times and not been mailed.......ever
Perhaps you set "Send me an email, when i have mail at plentyoffish" to no? I rather like being told when I have messages, but that also allows the regular site mail - See Below.
Hate to break the news, sparky, but I run a message board myself and I have access to all the passwords if I needed them for some reason
That's bad design, as the admin you should not *need* the passwords to read anything else. But I'm done talking about that, it's unimportant, and by itself it's acceptable.
This is the problem:
From: Plentyoffish To: Me Subject: davidgro New matches for April 10
Hello davidgro,
Thank you for signing up on {Date and Time}. Remember your password is {MY PASSWORD} {url} is larger then all other free dating sites combined.
View your latest matches here --> {url} ... | |
|
~iiCe~
| Joined: 7/26/2005 Msg: 11 | |
| E-mailing of passwords Posted: 4/10/2006 3:21:11 PM | I guess I have nothing on here to hide from anyone... I stay logged on at home.. if someone wants to check it out... they can... I trust they wouldn't do anything stupid... and there really isn't anything they wouldn't hear about...
sorry I don't see the drama....
don't like it... you can always delete your acct... | |
|
late™
| Joined: 1/9/2005 Msg: 12 | |
| E-mailing of passwords Posted: 4/10/2006 3:31:16 PM | This is a normal practice, a proactive measure because sometimes, ...people forget.
The password is sent to them (so they have a record of it on THEIR PC), via an email address provided by the person who created the account, not:
around the 'net at random.
If you have security issues concerning your computer, email accounts, etc.; see to them.
They shouldn't have such easy access to mine.
Your job | |
|
| E-mailing of passwords Posted: 4/10/2006 3:51:05 PM |
This is a normal practice
It is not. No other website automatically sends the password more than once, when the account is first created. And if it was only that one time then I wouldn't complain. (because That is a normal practice, so we have a record of it. But not every week.)
a proactive measure because sometimes, ...people forget.
That's the reason for the "Forgot Password" link. | |
|
| E-mailing of passwords Posted: 4/10/2006 3:57:08 PM | Isn't there a way to not have your matches sent to you or is this default? Maybe that's the problem, I'm just guessing. | |
|
| E-mailing of passwords Posted: 4/10/2006 4:02:15 PM | I stand corrected. It was in my yahoo mail under the "latest matches" mail. I never open that one. I'm sorry. I misunderstood the original question.
I still don't see the big deal. If someone is standing there....don't open that mail. It's clearly marked: brawnydog New matches for April 10 ....as opposed to: brawnydog You have new mail @ Plentyoffish.com | |
|
| E-mailing of passwords Posted: 4/12/2006 9:50:58 AM |
I still don't see the big deal.
It's because of how e-mail works; in a sense it really is sent "around the 'net at random." - and anyone at any of the stops between POF and my screen could snoop on it. I'm not so paranoid that I am concerned when I get my password e-mailed once (though some people are), but when it's on a predictable schedule it's worrisome. | |
|
| E-mailing of passwords Posted: 4/12/2006 10:17:08 AM | "it really is sent "around the 'net at random." Someone please tell me this isn't true!! Do you really think that people would have online bank accounts, buy things off the net if this were true? I know there are security measures in place to protect people's private info and while it can be hacked into and stolen, sure it's not just floating around randomly!! | |
|
| E-mailing of passwords Posted: 4/12/2006 11:50:34 AM |
Someone please tell me this isn't true!!
Take a look at the full headers of some e-mails. Each one of the "Received: " lines is a computer that the message went through. The only reason I am unconcerned by one-time mailings is that there is so much mail per second that normally it isn't worth a crook's time to try and sort all of them for personal info.
But when it's once a week, it's no longer random and someone Could decide that it was worth it to steal passwords. (This is just a dating site, but some people use the same passwords and usernames at their bank, online stores, etc.)
Whether or not this is likely, we shouldn't give them such an easy opportunity. (Especially when it's so easy to fix.) | |
|
| E-mailing of passwords Posted: 4/12/2006 12:33:26 PM | david grow up, if people are too stupid to use the same password for their bank account and pof, pof can't be held responsible. btw, nice glasses really geeky. keep the w, it's free. | |
|
libbyv
| Joined: 8/17/2005 Msg: 20 | |
| E-mailing of passwords Posted: 4/13/2006 5:36:09 AM | | I have emailed administation to help me change my password which I have not heard any response from them. | |
|
| E-mailing of passwords Posted: 4/13/2006 6:39:09 AM | Change Username Or Password
How Do I Change My Username Or Password?
Login to Plentyoffish.com and click on ‘Edit My Profile’ at the top of the screen. Next, click on ‘Edit More Registration Detail HERE’ and you’ll be able to change your username and password. Click HERE to change your username or password. | |
|
| |
| E-mailing of passwords Posted: 4/13/2006 9:56:29 AM | | most of the people that complain are married, It acts as sort of a filter. | |
|
| E-mailing of passwords Posted: 4/13/2006 11:45:41 AM |
most of the people that complain are married, It acts as sort of a filter.
I don't see how it could be an effective one - I'm sure they must just set POF to use an e-mail address that their spouse doesn't know about. (for that matter, if the spouse could see the e-mail with the password then they could see the ones with replies from other users, and there would already be trouble) | |
|
libbyv
| Joined: 8/17/2005 Msg: 25 | |
| |