Ouch… This should never be possible, in any world. If the password can be emailed, it can be seen. If it can be seen, it can be stolen.
Are you saying that the parent poster is giving incorrect information?
____@infosec.pub 1 year ago
Are you saying that the parent poster is giving incorrect information?
Ouch… This should never be possible, in any world. If the password can be emailed, it can be seen. If it can be seen, it can be stolen.
ono@lemmy.ca 1 year ago
Yes, mosiacmango’s comment echoed what others had said earlier (right down to specific words that I used in the original thread and here), but then went further with this conclusion:
Everything about that statement is false. While the circumstances made it seem likely that the screenshot was old, it was not clearly so, and in fact, the issue is still present. I checked it. A registration email from the test I ran yesterday looked just like the screenshot in question, cleartext password and all.
Given that Larian reported the issue fixed three years ago, it’s possible that they fixed it locally and some time later upgraded to a new version of the forum software, thereby overwriting the local fix.