Details
-
Bug
-
Resolution: Done
-
P2: Important
-
None
-
None
-
None
Description
After registering for the bug tracking system, the system send my provided password back in plain text, in an unencrypted email.
In my opinion, this is a serious security flaw.
If I provide the password, I want it to be kept secret.
If the system generates a password, it has to be sent to me, of course.
Currently, I have to immediately delete the confirmation mail, which completely destroys its purpose of being a long-term remainder.