zmal writes "I recently purchased a new Vista system (necessary for work), which came with a free subscription to the Norton suite of security tools. As part of the installation, Symantec has you set up a "Norton Account". The confirmation email sent back from Symantec on creating a new account includes a link with the username and password for the new account in plaintext:
Received: from excu-mxob-1.symantec.com (excu-mxob-1.symantec.com [198.6.49.12])
by XXXXXXXXXXXXXXXXXXXX (Postfix) with ESMTP
for ; Thu, 30 Aug 2007 23:28:38 -0700 (PDT)
Received: from cup2opsmtapin02.ges.symantec.com (cup2opsmtapin02.ges.symantec.com [155.64.1.103])
by excu-mxob-1.symantec.com (8.14.1/8.14.1) with ESMTP id l7V6Rml6031676
(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)
for ; Thu, 30 Aug 2007 23:27:48 -0700
Received: from excu-dns-1.symantec.com ([198.6.49.190])
by cup2opsmtapin02.ges.symantec.com with esmtp (Exim 4.67)
(envelope-from )
id 1IQzyu-0004NQ-30
for XXXXXXXX@XXXXXXXXXX; Thu, 30 Aug 2007 23:27:48 -0700
Received: from nav1drmmtacl02.conxion.com ([206.204.54.213])
by excu-dns-1.symantec.com with esmtp (Exim 4.52)
id 1IQzyt-00008C-WB
for XXXXXXXX@XXXXXXXXXX; Thu, 30 Aug 2007 23:27:48 -0700
Received: from ussj-ebeapppdcl01.ges.symantec.com ([192.168.78.132] helo=ussj-ebeapppdcl01)
by nav1drmmtacl02.conxion.com with esmtp (Exim 4.52)
id 1IQzyt-00037r-Ub
for XXXXXXXX@XXXXXXXXXX; Thu, 30 Aug 2007 23:27:47 -0700
Message-ID: 2107168635
Date: Fri, 31 Aug 2007 06:27:47 +0000 (GMT)
From: NortonAccount@symantec.com
To: XXXXXXXX@XXXXXXXXXX
Subject: One final step to confirm your Norton Account (Message-ID=2107168635)
(message contents...)
href="https://www.mynortonaccount.com/?email=XXXXX XXX%40XXXXXXX.com&password=XXXXXXXX"
I've included the message headers to show that the message is indeed coming out of Symantec, up to the point where it reaches my ISP's mail servers.
I expect better from all companies that do business on the Internet, but especially from security companies registering account details for security products. I tried to email Symantec about this, but mail to the contact addresses I found all bounced as undeliverable."