send reseller password

From: Josh Levine (joshl@levindustries.com)
Date: Tue Jul 29 2003 - 22:42:29 EDT


Is it worrisome to anyone else that there's now a page that you can
request to have any reseller's password emailed in plain text to the
emergency contact address with no verification required whatsoever?

I contacted OpenSRS support to ask them to disable this "feature" from
my account, and I received this response:

> Please note that this feature was added at the request of many
> Resellers.
>
> Actually, all of our servers will send Email encrypted but only if the
> receiver supports it.
>
> If your Email provider does not support SSL encryption, you may want to
> consider getting a webmail account for use as your emergency contact.

Perhaps I'm missing something, but are the OpenSRS servers really using
SSL to encrpt email?

--Josh Levine



This archive was generated by hypermail 2.1.3 : Tue Oct 19 2004 - 23:37:45 EDT