I totally agree with Falko. Passwords have to be stored as safe as possible on the server. Everything else compromises security and therefore is not an option at all.
You can think about mechanisms to automatically create new passowords and send them as e-mail with a confirmation link, but that's it. If someone likes to use a common password (which he shouldn't) and cannot remember (How common is it, then?) then he/she will have to change it back afterwards.
It's okay to have the system assist a user if he/she forgot a password (which should not occur anyway) but it's not okay to compromise security, not even as an hidden option in the config file.
What I would like to see is a password field for newly created items that's filled with a relatively secure random password per default. Make it an optional setting, if one Admin doesn't like it and/or let him/her define the rules for passwords like "must contain digits", "must contain special characters", "must be at least x characters long", "must contain upper and lower case", etc.
|
Recent comments
23 hours 17 min ago
1 day 5 hours ago
1 day 9 hours ago
1 day 11 hours ago
1 day 19 hours ago
2 days 5 hours ago
2 days 6 hours ago
2 days 9 hours ago
2 days 14 hours ago
2 days 14 hours ago