- Joined
- Jan 25, 2022
- Messages
- 15
- Reaction score
- 4
I'm very concerned about the very lax security of the welcome email, sending plain text passwords in an email is a complete no no these days.
Is there a way to prevent welcome emails being sent upon user request (e.g. via the mobile app)?
I know I can edit the email template and remove any passwords and qr codes from the email body but I can't find a way to prevent it sending the provisioning file attachment. The attachment has the tunnel password, extension id and extension password right there in plain text, it's even handily marked up for any attacker (in xml) so they know which password should be entered where
Is there a way to prevent welcome emails being sent upon user request (e.g. via the mobile app)?
I know I can edit the email template and remove any passwords and qr codes from the email body but I can't find a way to prevent it sending the provisioning file attachment. The attachment has the tunnel password, extension id and extension password right there in plain text, it's even handily marked up for any attacker (in xml) so they know which password should be entered where