Go Back   HostGator Peer Support Forums > Public Forums > Suggestions

Notices

Reply
 
Thread Tools
  #1  
Old 12-11-2009, 12:20 PM
yzr yzr is offline
Hatchling Croc
 
Join Date: Nov 2009
Posts: 32
Lightbulb What's the purpose of a password?

What's the purpose of a password if, on first mistyping it, it is automatically emailed to you, plain text, without you even requesting it?

This is currently the case with HostGator's ticket system (it seems that in other password-protected subsystems in HG password handling is done right).

I would expect a professional and reputable company like HostGator to email password upon explicit request by user only.

Reply With Quote
  #2  
Old 12-11-2009, 06:35 PM
GatorLBrower's Avatar
GatorLBrower GatorLBrower is offline
HostGator Staff
 
Join Date: Feb 2008
Location: Texas
Posts: 1,408
Default Re: What's the purpose of a password?

The password is emails to the email address for the account, not the person requesting it. This would only be a problem if the person making the request has already compromised your email account and gained control over it, at which time this is probably a moot point since most people use IMAP and don't delete the original email with the password in it.
__________________
Larry Brower, CCNA
Linux System Administrator II
Hostgator.Com, LLC

Reply With Quote
  #3  
Old 12-13-2009, 10:20 AM
yzr yzr is offline
Hatchling Croc
 
Join Date: Nov 2009
Posts: 32
Default Re: What's the purpose of a password?

Larry, thanks for your answer.

I am afraid, however, that I didn't make the point clear enough:

The main reason for the existence of SSL is the possibility that a hacker that happens to be on on one of TCP/IP hops can intercept whatever transmission goes through its node.

Slim possibility? Probably. But then why do financial institutions, ecommerce sites (and other sites handling sensitive information) insist on using SSL?

These sites insist also on strict and methodical password handling. In fact, HostGator itself, in billing and admin accounts, will not email a password (clear text) unless explicitly requested by the user. There is a valid reason for this.

Why not simply adopt the same practice for your ticket subsytem as well? You already have this practice established and working well in your other subsystems.

Reply With Quote
  #4  
Old 12-13-2009, 06:16 PM
GatorDHanna's Avatar
GatorDHanna GatorDHanna is offline
HostGator Staff
 
Join Date: Sep 2008
Location: United States
Posts: 572
Default Re: What's the purpose of a password?

You have a good point. We are certainly concerned about security and there isn't a reason we can't include a "forgot password" link that only displays or emails the password per the user's request.

I'll pass this feedback onto our programming team.
__________________
Douglas
Customer Service Manager
HostGator.com LLC
1-866-96-GATOR
Reply With Quote
  #5  
Old 12-14-2009, 02:00 PM
yzr yzr is offline
Hatchling Croc
 
Join Date: Nov 2009
Posts: 32
Thumbs up Re: What's the purpose of a password?

Doug, thank you very much. One of the great things that I like about HostGator is that it listens to its customers.
Reply With Quote
  #6  
Old 12-16-2009, 10:40 PM
GatorDHanna's Avatar
GatorDHanna GatorDHanna is offline
HostGator Staff
 
Join Date: Sep 2008
Location: United States
Posts: 572
Default Re: What's the purpose of a password?

This change has been made. Let us know if you have any other suggestions.
__________________
Douglas
Customer Service Manager
HostGator.com LLC
1-866-96-GATOR
Reply With Quote
  #7  
Old 12-18-2009, 07:41 AM
alemcherry alemcherry is offline
Swamp Croc
 
Join Date: Mar 2008
Posts: 211
Default Re: What's the purpose of a password?

Quote:
Originally Posted by GatorDHanna View Post
This change has been made. Let us know if you have any other suggestions.
Wow.. that is a welcome change.
More than just security, used to be a confusion. If you just missppell the password, it is changed and emailed to you. And if you try again with correct password, it is reset again. Thanks for listening to the customer's point . Cheers!
Reply With Quote
  #8  
Old 12-18-2009, 07:59 AM
mrintech's Avatar
mrintech mrintech is offline
Royal Croc
 
Join Date: Nov 2009
Location: India
Posts: 411
Smile Re: What's the purpose of a password?

Thanks HostGator
__________________
MrinTech| Coupons | Facebook
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
My Suggestion for SECURITY PURPOSE (Dedicated Server Owner) ownerhosting Suggestions 2 10-19-2008 05:00 AM

All times are GMT -5. The time now is 11:08 AM.