Forums / DQ: Horizons / Bug reports / Automatic emails
Posted ByMessage
Emperor L
[ Posts : 1237 ]
[Post Date: 21-Jun-2008 02:05]

I already emailed about the activation email. Wher the name still says Delta Quadrant Humans.

But I just tested the retrieve password option on the main page, and the email it sends also says Delta Quadrant Humans.

Also, is that really a secure way to get your password? Because anyone who knows your username (isnt hidden) and email (anyone can get this) can change your password. Maybe have a security question or something also could help?


This message was edited by Emperor L
Maverick
[ Posts : 1331 ]
[Post Date: 21-Jun-2008 13:05]

Quote
I already emailed about the activation email. Wher the name still says Delta Quadrant Humans.

But I just tested the retrieve password option on the main page, and the email it sends also says Delta Quadrant Humans.

Also, is that really a secure way to get your password? Because anyone who knows your username (isnt hidden) and email (anyone can get this) can change your password. Maybe have a security question or something also could help?


This message was edited by Emperor L


1. Subject for activation and password retrieval emails fixed.
2. Yes, someone who knows your email and user name, could change your password, but he wouldn't get it. This is a risk we have to admit. The problem with additional hint/question is that most people forget what they wrote and result in a new account or even worse leave the site. In future we will add a secure image to prevent bots from auto registering and other ugly stuff.

Emperor L
[ Posts : 1237 ]
[Post Date: 21-Jun-2008 13:16]

Quote
2. Yes, someone who knows your email and user name, could change your password, but he wouldn't get it. This is a risk we have to admit. The problem with additional hint/question is that most people forget what they wrote and result in a new account or even worse leave the site. In future we will add a secure image to prevent bots from auto registering and other ugly stuff.



Oh, ok. So it will only accept the email address in your account page. So, if someone entered their own email and your username, then they would not get it? Thats ok then I guess.


Maverick
[ Posts : 1331 ]
[Post Date: 21-Jun-2008 13:40]

Quote
So, if someone entered their own email and your username, then they would not get it?
Right, system checks if email belongs to specified user name.