Secure login
The login form is currently unprotected -- should post to an SSL-protected login form. Similarly, users should not receive passwords via email after signing up (or ever).
-
yes - *very* poor security practice, especially emailing passwords in the clear. 'Beta' is no excuse, security should come first.
›3 Replies -
