Community Page
- bobcaswell.com Jump to website »
-
Subscribe -
Community
-
Top Commenters
-
Popular Threads
-
Recent Comments
- Thanks for helping provide better perspective. Sometimes, in all the noise, we forget that protesters are usually just quiet neighbors. It takes an especially awful situation to get the noise level...
- Thanks for the comment. The more I read up on the situation, the more I understand why you (and others) are very upset about all this.
- "nice job, with your piece on the Bellevue demostration on Iran and awareness is all we can bring to the problem in Iran. Thanks Bob for his humane and objective view. Most of us have never...
- Thank you for the post. It's logical and repectful. I was there, mad as hell ( guy in red shirt...)
- Thanks for the thoughts, Bighappy, hopefully Bing will get to the point where you'll want to use it for tech info or classic cars. When you say that 93% of your searches have "absolutely...
Bob Caswell
Media consumer, tech enthusiast, and bloggerPet Peeve: Why do companies still send me my password through email?
Started by Bob Caswell · 10 months ago
2 years ago
That said, the "correctness" of selected feature is a balance between benefit and risk. For most people e-mailed passwords offer a risk is lower than the convenience. The real issues are 1) risk and benefit are arbitrary and individually defined by the user, not the website creator and 2) no alternative risk/benefit choice is offered by the website creator. In the first case the problem space is ignored and in the second the solution space is ignored.
I've used websites where e-mailed passwords were *not* used for password recovery and the chosen alternative was so onerous compared to the value of what I was trying to get done that the *lack* that e-mailed passwords both incensed me and reduced the value of use the website to me.
2 years ago
Emailing passwords is bad form, especially if you can't opt-out of the password being emailed to you.
2 years ago
And J, to quibble a bit, I have to say that I don't necessarily agree that "the core problem is to use the same password everywhere." The problem I'm talking about (passwords being emailed) would still be the exact same problem even if I picked a brand new password exclusively for my new login. If I care anything for my privacy / security, I don't want it emailed to me, plain and simple.
2 years ago
Anyways, I don't care even a few companies do that because it's my habit to use a 5 to 8 characters long password during the signup process. No matter if it's a big company like IBM or a new startup, I do change my password after receiving the account activation email.
Even in the current Web 2.0 era, I've experienced a few Web 2.0 startups sending passwords included in their account activation email. They really need to understand that this is the year 2007!
2 years ago
http://passpack.wordpress.com/2007/04/06/how-sa...
An online Password Manager that sends you your master password via email. (I know it's not nice to point a finger like this, but I'm honestly shocked)
2 years ago