Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


To all the LET VPS providers: why do you keep sending the password in plain text?
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

To all the LET VPS providers: why do you keep sending the password in plain text?

untitleduntitled Member
edited November 2023 in General

I've subscribed to more providers that advertised their offers on LET - thank you again LowEndTalk! :blush:. However most of them keep showing or sending me per email the password I've chosen for my new VPS with no protection as plain text. Emails telling me the VPS was activated, opened tickets about some different topic with the note that my password is "text" and so on...
I mean, we know you can see what we're doing, but using this sort of reminders reduces the user's privacy to zero. Besides that as you may know the email isn't the securest way to share sensitive data.
I hope maybe all the providers will change that in the future.
Thank you and I hope you'll all have a great BF 2024 :smiley:

Comments

  • tentortentor Member, Patron Provider
    edited November 2023

    Use SSH public keys then (it will prevent leak of your password)

    VirtFusion has a warning in their email template:

    {% if server_uses_password %}
    
    
    To improve security, we recommend that you add an SSH key when creating a server.
    {%- endif -%}
    
  • just change the password when you login.

    Thanked by 1bdl
  • untitleduntitled Member
    edited November 2023

    @BruhGamer12 said:
    just change the password when you login.

    I am aware of this option and I use it in such cases.
    It's just the idea of handling a password like a password

  • its actually to encourage you to change upon first login.

    Thanked by 3bdl DanSummer nick_
  • balrammbalramm Member, Host Rep

    If I don't send passwords by emails, most of my clients will get offended that they have to login to our client area to retrieve passwords, There is 1% of you who think it should not be in plain text remaining 99% choose to reset no matter how securely you send or they use ssh key.

    Thanked by 1jfreak53
  • As someone who actually has worked for some providers, I can guarantee you that if the provider doesn't include the password in the emails (yes, in plain-text), you will get numerous tickets asking where/what the password is.

  • so how should it be done? snail mail?

  • MannDudeMannDude Host Rep, Veteran
    edited November 2023

    We don't send it. It's randomly generated internally for the purpose of creating a VPS, but not sent to the customer. VPS welcome email tells you how to add your key or how to add / change the pass from the control panel.

    No reason for your service provider to know your root pass unless they're managing your server.

    Thanked by 2Zyra ariq01
  • Just send one time link instead.

    Thanked by 1babywhale
  • yoursunnyyoursunny Member, IPv6 Advocate

    Our Antarctica IPv9 VPS not only send plain passwords but also encourage customers to post their passwords on LET.
    We have advanced security based on brain connect technology, so that passwords are not at all important.

    Thanked by 1BruhGamer12
  • NeoonNeoon Community Contributor, Veteran

    Most of the Providers are using the same Billing or/and VPS Management software.

  • shruubshruub Member
    edited November 2023

    @yoursunny said:
    Our Antarctica IPv9 VPS not only send plain passwords but also encourage customers to post their passwords on LET.
    We have advanced security based on brain connect technology, so that passwords are not at all important.

    IDontKnowHowPasswordManagersWork2020

    (at least you don't know that my email is [email protected])

  • @cybertech said:
    its actually to encourage you to change upon first login.

    interesting, considering the average online customer.

  • defaultdefault Veteran
    edited November 2023

    Password must be sent in plain text if there is no SSH key option. Most customers will open tickets if they don't have that password easy to find in front of them.

    The best solution is to simply include in email a notification like this: "Please change the password on your first login and don't forget to always use very strong and complex passwords everywhere!"

    Thanked by 1farsighter
  • huntercophuntercop Member
    edited November 2023

    KISS - keep it stupid simple

Sign In or Register to comment.