Transmitting Account Information via Email
Hello,
Not sure if this is the right place to put this, but I hope so, because I really am looking for some clarification on this issue. Lots of questions... here goes... I am curious about what practices would be considered acceptable or unacceptable related to transmitting account information to user's email addresses.
Is it inappropriate to email a customer their password to their registered email address in an unencrypted format?
What is the real potential for someone to intercept an email containing relatively sensitive information like this?
Is there really any totally secure way to handle such a situation where a user forgets their password?
If anyone has some web sites that offer best practices related to this kind of thing, please post them.
Thanks!