Alexia wrote in post #18738494
Having to use Google to find out where to change my password,
The Password Reset link is on every page, when an unlogged user view the forums. If you are logged in, you could just ask here if in doubt.
HOSTED PHOTO
please log in to view hosted photos in full size.
finding out that the site was relaunched without the ability to change a password,
Wrong. You can change your password.
and then find that the utility is stored under a link with a terrible name is a sign of poor design.
When you use the site for more than 1 day, you will know what FYEO is, it is no more terrible than UserCP or that cog icon.
Adding on to that the password change form recommends saving it in a plain text file locally for backing it up!
"TYPE YOUR PASSWORD INTO A PLAIN TEXT EDITOR (like Notepad), SAVE IT AND COPY IT FROM THERE TO THIS FORM. "
There no recommendation to save locally. Nowhere it is advised that plain text file is NOT saved as a password protected file/achive and under a password protected computer account / device / cloud. These things are common daily computing routines and the save recommendation is there because password should be so complex that you should NOT remember it easily. Do you trust commercial/freeware companies saving your passes? If so, which is more secure, your own device/USB stick/removable drive or their cloud?
I'll change that text to more clear:
"TYPE YOUR PASSWORD INTO A PLAIN TEXT EDITOR (like Notepad) AND COPY IT FROM THERE TO THIS FORM. THAT ENSURES THERE WILL BE NO TYPOS. Backup your password to a secure device/service."
Time for some penetration testing.
Done.