I dont get what the big deal about sending password via email is. Pretty much every site ive ever signed up to does that. It's not like you have any money / private details on pcw, so you should only be worried if someone has access / or can gain access to your email account. You could always go mad and delete the email >_>. Or if you mean that it could get intercepted, well, then its the email site thats flawed - and you shouldn't use the same password for every site anyway.
These 2 statements show a basic flaw in your understanding of the security involved. You tell people not to worry about their passwords because they're strongly encrypted on the server side, but you don't care that they're being sent in plain text across the net. It's analogous to creating a very strong password for something then writing it down on a piece of paper and leaving it sitting next to the machine (and you just need to ask some Russian spies how that works out).
Just because it's a common (but not standard) practice to send passwords in plain-text across the Internet doesn't mean it's secure or good practice. How many popular services are (or have been) open to SQL injection attacks? The answer is quite a lot of them. What you should do (instead of sending the password through email) is to allow users to request an email to be sent to a given address with a validation link to re-set the password. That can still be compromised if an attacker has access to the email account in question, but it's a much safer practice.
Yet this forum sends passwords to your email too. Sigh.
You're all going on as if it's some military website or it has your bank details. Use a unique password and theres no worries, the worst that can happens is someone does something to your account.
This forum sending plain text email is a much bigger flaw, as its likely that people use the same password as their lfs account.
Pixel Car Life came about from someone with an original idea while Pixel Car World saw a good original idea and copied it now thinking it is their own?
Think CLC and then all the copycat cruise servers that think theirs are original.
What he said was nonsense anyway. I have been running this forum for 4-5 years under various different names. I created the original without even knowing that PCL existed. So it was probably the same "original idea" that i got my inspiration from as PCL did. I can't remember the original name of my forum, but then it was changed to MCW (manga car world) for 2 years and now last year it was changed to PCW (pixel car world). It has been hosted on various boards - invisionfree, a free phpbb host and now an actual phpbb forum on domain and server. Oh, and i never said it was "original", obviously its not the first of its kind but its been going longer than pretty much all. Infact, most people are actually trying to rip us off now, there are many, many copies which have just directly copy and pasted our things. All our cars have been found, put onto the pcw base, and the specifications all written from scratch.
So I wish people would keep their opinionated nonsense to themselves, or at least get their facts straight! That's really f**ked me off - If only you knew how much work has gone into this over the past 4/5 years.
In response to your question BlakjeKaas:
Pixel car world is run completely differently. On PCL anyone can do what the hell they like basically, everyone has there own little part of the forum, nothing seems to match. On PCW we are more about being a fair game, there are more rules and it's about being realistic and fun. If you come on you will instantly see the different, its much more organised than PCL.
This I can agree with, I have an account on both sites (Well, I did, I dont have the time or resources anymore) & PCW was far far more understandable & easy to follow then PCL, PCL is just a bit of a mess if I'm honest...
That is EXACTLY what i was aiming for, and i'm glad you can see it! I went on PCL about 1.5 years ago now, and i was like uhhh, what do I do? Why does everyone have there own shop, all charging different prices for parts? Why do people have 1 billion cars each? Why do members judge the races? (we have a formulaic calculation). Then they reset all the memberships and i haven't signed up since.
And I'm big enough to admit when I'm wrong. And i was wrong. I didn't think sending password through email as such as big deal, as a lot of sites do it. I now know that it could be a security flaw and I have been searching for a way to stop the forum sending them (As i didnt chose this, it was automatic).
But please stop being pedantic, what I said about thinking security wasn't a flaw, is not really related. I was just uninformed in that particular area, as you can see from my replies.
There's a difference between being pedantic and having a sysadmin/networkadmin/site owner etc not only lacking technical knowledge (i.e. not thinking sending passwords in plain text was an issue) but also trying to portray that it wasn't an issue because the passwords were well encrypted on the server side. If I was to join your site I'd like to think it was run by someone competent. Sounds harsh, but people looking for security flaws don't care about hurting your feelings either.
I meant pedantic about comparing the point i made to the point he made.
But i understand completely that people are worried about security, especially these days, you can't be too careful.
To be honest with you, I didn't even know that the forum sent out passwords to peoples emails, seeing as I've never signed up to my own forum. But now i know about it, I will work on a solution.
I'll get back to you when i've found a solution.
Andy