|
If you
ever send out any form of a password, temp or not, it's insecure. If you're
asking them personal questions anyways, through an ssl connection, there's no
reason to even involve their email, just immediately let them in and make them
reset their password. Also, the passwords should be stored in the database as
hashes of the actual password, so there's no way for your "designer's" idea to
work at all since you would never even know their password. The only reason any
companies send out passwords via email is to verify that the email address is
valid so they can legally spam you to death. It also makes it harder for bots to
script setting up accounts at your site if you have a unique restriction on
email addresses, so that for every account the bot creates, it needs an email
address.
Bruce Dunwiddie
|
- [KCFusion] Adaryl Wakefield
- RE: [KCFusion] cfhelp
- [KCFusion] Adaryl Wakefield
- RE: [KCFusion] Glenn Crocker
- Re: [KCFusion] Adaryl Wakefield
- RE: [KCFusion] Glenn Crocker
- Re: [KCFusion] security Adaryl Wakefield
- [KCFusion] HIPAA Keith Purtell
- RE: [KCFusion] security Glenn Crocker
- RE: [KCFusion] Bruce Dunwiddie
- RE: [KCFusion] Glenn Crocker
- RE: [KCFusion] Bruce Dunwiddie
- Re: [KCFusion] Matt . Bassham
- [KCFusion] DNS issues OT Adaryl Wakefield
- RE: [KCFusion] DNS issues OT Glenn Crocker
- Re: [KCFusion] DNS issues OT Adaryl Wakefield
- RE: [KCFusion] DNS issues OT Glenn Crocker
- Re: [KCFusion] DNS issues OT Adaryl Wakefield
- RE: [KCFusion] DNS issues OT Bruce Dunwiddie
- [KCFusion] Justin Amirtharaj Felix
