Hacker News new | past | comments | ask | show | jobs | submit login

In our user management portal, whenever tech support opens the Create New User or Reset User Password page Chrome helpfully fills their administrative password into the user's password field.



So in your user management portal, you assign new users or replace your lost passwords with passwords you set, thus you know? Oh my days! Generate it randomly and mail the user, or better, mail them a link to reset/create password page. Otherwise, just make it a plain input field, because if you know it, it's not hidden anyways.


Every hurdle vs. proper security has been non-technical. Slowly making progress :-)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: