This thread is frustrating. Everyone seems more interested in nitpicking the specifics of what OP is saying and are ignoring that a forum sends you your password (not an automatically generated one) in an email on registration.

  • El Barto
    link
    fedilink
    7
    edit-2
    9 months ago

    Are you saying that the parent poster is giving incorrect information?

    Edit: Oy, straight from their membership administration docs (emphasis mine):

    Additionally, using the buttons below, you can delete the user, email the user’s password to him/her, (etc)

    • ono
      link
      fedilink
      English
      7
      edit-2
      9 months ago

      Are you saying that the parent poster is giving incorrect information?

      Yes. mosiacmango’s comment repeated what others had already said (right down to specific words that I used in the original thread and here), and then jumped to this conclusion:

      Pretty clear that this is a very old screenshot of what is now a non issue.

      Everything about that statement is false. While the circumstances made it seem likely that the screenshot was old, it was not clearly so, and in fact, it turns out the issue is still present. I checked it. A registration email from the test I ran yesterday looked just like the screenshot in question, cleartext password and all.

      Given that Larian reported the issue fixed three years ago, it’s possible that they fixed it locally and some time later upgraded to a new version of the forum software, thereby overwriting the local fix. Perhaps mosiacmango should have considered that before posting incorrect speculation as if it were fact.

    • @____@infosec.pub
      link
      fedilink
      49 months ago

      Ouch… This should never be possible, in any world. If the password can be emailed, it can be seen. If it can be seen, it can be stolen.