Passwords sent in clear text?
[email protected] (Tobias Lohr) Thu, 31 May 2018 22:34:33 +0200
| Newsgroups | php.pear.webmaster |
|---|---|
| Message-ID | <03dfd65a-27f5-4a79-93fc-c37b46540ad4@Spark> |
--5b105c5e_7c3dbd3d_100e3 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline Dear pear webmasters, On November 3rd, 2017 I=E2=80=99ve received an e-mail from=C2=A0bounce-no= -user=40php.net referring to a password for a bug report (=236627) I once= created back on 2006. It feels to me, that my password at these times has been stored in cleart= ext and not hashed (which is not according to security best practices), a= s otherwise the password could not have been sent via e-mail 12 years aft= er I have created the bug report. Can you please clarify why that happened, how you store passwords, and in= form me please, what information you have stored about myself (e-mail: to= biaslohr=40gmx.de). If you still store information about me, I want to reset my password now,= but the reset password page errors with =22Unknown user =E2=80=9Ctobiasl= ohr=E2=80=9D or Unknown user =E2=80=9Ctobiaslohr=40gmx.de=E2=80=9D. If th= is is not possible, please - after sharing the data you have stored about= me, delete all my personal data you have stored about me. I=E2=80=99m re= fering to the European GDPR here. Thanks you very much, Tobias Lohr --5b105c5e_7c3dbd3d_100e3--