Page 1 of 1

Installation Assistant sends cleartext password by mail

Posted: Wed Apr 26, 2017 9:16 pm
by tristan
IMHO it would be better to not include the admin password in the mail thats sent after a successful installation. Since email is inherently insecure and know the password is saved in at least one location (mailbox) in cleartext.

Maybe we could skip the "Your installation of CMS Made Simple is complete." email altogether since we already know we installed the CMS successfully because the Installation Assistant told us and we're going to set the Mail Settings properly after we login the first time anyway.

Re: Installation Assistant sends cleartext password by mail

Posted: Wed Apr 26, 2017 9:40 pm
by calguy1000
You can choose not to receive the email by turning on the advanced mode.

But... people have requested that we NOT drop the email.

Re: Installation Assistant sends cleartext password by mail

Posted: Wed Apr 26, 2017 9:58 pm
by tristan
Shouldn't it be an option to send the email in advanced mode and make it default not to send out an email to make new installs a little more secure?