You are reading a single comment by @Velocio and its replies. Click here to read the full conversation.
  • Ordered a couple of bags of the Gaslight for the office, thanks Steve.

    One thing though... the password being sent via email when you set up an account. Tut tut.

    1. You shouldn't have the password, it should be hashed and impossible to be reversed back to plain text.
    2. Even if you have plain text or a reversible encryption... you should never ever send the password via plain text.

    Whilst we're here... most of your site is not SSL, actually is any of it? You should get your site behind SSL ASAP. If you sign up for the company I work for SSL is free https://www.cloudflare.com/ but it takes a couple of days for SSL to be activated.

    Not only would that protect your customers and their details, but Google considers SSL to be such a good thing that they increase your search engine placement if you have SSL. It's considered a positive signal by them.

    But aside from non-SSL worries, I look forward to the coffee :)

About

Avatar for Velocio @Velocio started