latest stable versions: v150827 (changelog)

Old Forums (READ-ONLY): The community now lives at WP Sharks™. If you have an s2Member® Pro question, please use our new Support System.

Dangerous sending username/password in email?

Home Forums Community Forum Dangerous sending username/password in email?

This topic contains 4 replies, has 3 voices. Last updated by  Eduan 4 years, 10 months ago.

Topic Author Topic
Posted: Sunday Mar 4th, 2012 at 5:43 pm #7237

HI everyone. Sorry if this seems like a silly question, but isn’t it dangerous to have s2Member send out new user usernames and passwords together via email? Isn’t it possible that the username/password combination could be snooped or seen by certain nefarious people (spammers and the like)? I just don’t want any of my users’ accounts compromised.

I am nervous about sending this information out automatically to newly registered users. I think the safe thing would be to send the username alone and expect the user to remember the password he or she created during registration.

S2Member help says: “This email is sent to all new Users/Members. It should always contain their Username/Password”; management of this is at S2Member General Options -> Email Configuration -> New User Email Configuration -> New User Email Message ( click to customize )

List Of Topic Replies

Viewing 4 replies - 1 through 4 (of 4 total)
Author Replies
Author Replies
Posted: Monday Mar 5th, 2012 at 12:04 pm #7346
Eduan
Username: Eduan
Moderator

Hello Simon, thanks for your inquiry.

I understand why you would be worried.

As in the last paragraph, have you tried editing the email that will be sent to users? In there there’s a special replacement code that sends them their password, you can simply remove that replacement code.

You can do this under Dashboard -› s2Member® -› General Options -› Email Configuration.

I also invite you to check our KBA (Knowledge Base Article) on the subject:
Knowledge Base » Editing the New User Email Notification with s2Member®

Hope this helps. :)

Posted: Tuesday Mar 6th, 2012 at 3:45 am #7411
Staff Member

Thanks for the heads up on this thread.

Well, sending passwords via email is an standard practice on the web. A transactional email is sent to each new registrant, so they have it on file, in case they forget. However, if you’d rather not do that (and I do understand your point), you can simply remove that line from the email that is sent to new registrants. You’ll find that email here: Dashboard -› s2Member® -› General Options -› Email Configuration

Posted: Tuesday Mar 6th, 2012 at 9:55 am #7446

Thank you Eduán and Jason, for the quick replies. You guys are the best!

I really love the S2Member and Pro plugins. I thank you for creating such an excellent and apparently “lightweight” framework to manage memberships on our sites.

I have removed the password info from the outgoing new registrant email. This is the relevant section from the email template (might help others who wish to do the same):

Please keep the following IMPORTANT LOGIN INFORMATION for your records.

Site URL: http://mywebsite.com
Your Username: %%user_login%%
Your Password: (you set this when you created your account)

If you should need to reset your password, you may do so easily from the login box;
just click the "Lost your password?" link.

All in all, I am still not sure if it’s truly an important issue or perhaps I am all worried about nothing! For now, I’ll just play it on the safe side.

All the best to you both, again.

Posted: Tuesday Mar 6th, 2012 at 11:01 am #7458
Eduan
Username: Eduan
Moderator

You’re welcome Simon!
Thanks for the kudos!
:)

Viewing 4 replies - 1 through 4 (of 4 total)

This topic is closed to new replies. Topics with no replies for 2 weeks are closed automatically.

Old Forums (READ-ONLY): The community now lives at WP Sharks™. If you have an s2Member® Pro question, please use our new Support System.

Contacting s2Member: Please use our Support Center for bug reports, pre-sale questions & technical assistance.