Picto thématique

Rule n° 200 - The site doesn't communicate a password by email.

The risk that an e-mail can be intercepted or hacked can never be completely ruled out. Consequently, passwords must never be circulated in clear text, especially in emails. Some services may make an exception to the rule by offering you temporary passwords, but this is not the safest solution and should strictly be reserved for temporary solutions.

#Security #Development

Goal

  • Limit the risk of interception of passwords.

Implementation

When creating an account or in dealing with a request for a reset or reminder of the password, do not send it to the user by email. Only provide the password or its reset procedure online.

Control

Check that no password is sent to the user by email when creating an account or when requesting a reset or a reminder of the password.

By Opquast - Read the license