Lunarpages Web Hosting Forum

Advanced Lunarpages Assistance => Lunarpages Security Center => Topic started by: Pres on January 07, 2015, 09:38:17 PM

Title: LP password sent in plain-text email?
Post by: Pres on January 07, 2015, 09:38:17 PM
Hi everybody!

I just changed my master account password and got a shock when Lunarpages "helpfully" sent me an email message ("Welcome to Lunarpages - Critical Account Information") echoing my brand-new password back to me in plain text! duh Changed it again and got a new email announcing my password to the world. Gee thanks.

How do you, er, stop it from doing that?

I'm really hoping that there's a setting somewhere in the LP account area that takes care of this. Anybody know?
Title: Re: LP password sent in plain-text email?
Post by: MrPhil on January 08, 2015, 09:04:14 AM
I'll agree that sending an unrequested password in plain text is pretty stupid. The only time a password should be sent in the mail (if at all) is for a reset (autogenerated password). Even that might be avoided by emailing a link to an SSL-protected page, preferably one that asks a security question that only the customer would know the answer to (or for part of the credit card number).

You should complain on the Feedback and Review board, which is supposedly monitored by LP mangement.
Title: Re: LP password sent in plain-text email?
Post by: Pres on January 08, 2015, 06:04:09 PM
Thanks, I'll do that. (edit: where's that board?)

Has every Lunarpages user up to this point just been kinda letting this slide? It was odd that I couldn't find any obvious threads about the issue.
Title: Re: LP password sent in plain-text email?
Post by: MrPhil on January 08, 2015, 08:30:03 PM
Lunarpages Web Hosting Community > Lunarpages Review and Feedback