FULL DISCLOSURE: This blog runs on software from wordpress.org, which is completely different than the software at wordpress.com that offended me below.
Prior to becoming the management and virtualization junkie that you read here, I worked in data security. I was a security freak. No, strike that: I still am a security freak. I’m overly paranoid. I shred everything. I only use one credit card for online shopping. I get in arguments with my family when I find out that they use weak passwords. We don’t even say passwords out loud in my house, it’s that bad. I have passwords for securing other passwords in password “safes”. I keep my GPG keys on write-once media in a safety deposit box. Yes, I’m a freak when it comes to security.
So you can imagine my shock and horror a few days ago when I created a WordPress blog. I thought it was about time I had a personal, non-technology related blog, so I created both WordPress and Blogspot sites to compare features and usability. So I did my thing, created blog/site names for each service, matched those to an account name, and waited for my respective confirmation emails. With Blogspot, it’s tied to one of my GMail accounts, so no problems there. Google’s SSO Dashboard environment is awesome (btw, I’m addicted to iGoogle).
WordPress has an email confirmation system, notifying me when my account was set up and ready to go. However…and it’s a HUGE HOWEVER…the confirmation email from WordPress included my username, links to manage my blog, and MY PASSWORD IN THE CLEAR! THE FULL PASSWORD…IN THE CLEAR! If I seem aggrivated, well, welcome to my world. It’s freakin’ 2008, and a site as pervasive as WordPress is sending full passwords in the clear, via the most insecure data transport system ever devised, email?! C’mon!
I promptly logged into WordPress and changed my password, and will most likely end up at Blogspot b/c of this snafu. So kudos to WordPress for making my decision much easier.
And for your viewing pleasure, here’s the email from WordPress (pertinent user information changed, obviously).
New WordPress Blog: ExampleBlog
Your New WordPress.com blog has been successfully set up.
You can log in with the following information:
Username: exampleblog
Password: alice123
at http://wordpress.com
We hope you dig your new weblog. If you have any questions or comments, please let us know!