[Cryptography] Why is emailing me my password?

Markus Wanner markus at bluegap.ch
Wed Oct 2 01:44:43 EDT 2013


On 10/02/2013 12:11 AM, Joshua Marpet wrote:
> Low security environment, minimal ability to inflict damage, clear
> instructions from the beginning. 

Agreed.

There certainly are bigger problems on earth. And I really don't mind if
you move on and take care of any of those, first. :-)

> If the system and processes are not to your liking, that's
> understandable.  Everyone is different.

Please read my arguments, I'm not opposed to it based on personal
preference. Quite the opposite, I actually like web front-ends better
than email commands. But in this case, I think a mail based OTP solution
is better from a security perspective.

> There are other choices.  If you'd like to investigate them, determine
> an appropriate one, and advocate a move to it, that would be welcomed, I
> presume?

I did investigate. And I'm currently using smartlist. Whether or not you
or anybody else "moves" is entirely up to you or them.

If you use mailman, your users better be aware it doesn't follow best
practice regarding password handling, though.

And yes, smartlist certainly has its issues as well. If you know of any,
please let me know as well.

> No offense meant, in any way.  Please forgive me if offense is given.

No offense taken. And if it were, you're hereby forgiven. ;-)

Regards

Markus Wanner


More information about the cryptography mailing list