Passwords sent in clear text?

From: Date: Thu, 31 May 2018 20:34:33 +0000
Subject: Passwords sent in clear text?
Groups: php.pear.webmaster 
Request: Send a blank email to [email protected] to get a copy of this message
Dear pear webmasters,

On November 3rd, 2017 I’ve received an e-mail from [email protected] referring to a password
for a bug report (#6627) I once created back on 2006.

It feels to me, that my password at these times has been stored in cleartext and not hashed (which
is not according to security best practices), as otherwise the password could not have been sent via
e-mail 12 years after I have created the bug report.

Can you please clarify why that happened, how you store passwords, and inform me please, what
information you have stored about myself (e-mail: [email protected]).

If you still store information about me, I want to reset my password now, but the reset password
page errors with "Unknown user “tobiaslohr” or Unknown user “[email protected]”. If
this is not possible, please - after sharing the data you have stored about me, delete all my
personal data you have stored about me. I’m refering to the European GDPR here.

Thanks you very much,
Tobias Lohr


Thread (1 message)

  • Tobias Lohr
« previous php.pear.webmaster (#7123) next »