Rule n° 205 - Passwords are not communicated in plain text.
The risk that an e-mail can be intercepted or hacked can never be completely ruled out. Consequently, passwords must never be circulated in clear text, especially in emails. Some services may make an exception to the rule by offering you temporary passwords, but this is not the safest solution and should strictly be reserved for temporary solutions.
Goal
- Limit the risk of interception of passwords.
Solution technique
When creating an account or in dealing with a request for a reset or reminder of the password, do not send it to the user by email. Only provide the password or its reset procedure online.
Moyen de contrôle
Check that no password is sent to the user by email when creating an account or when requesting a reset or a reminder of the password.