It's unacceptable to transmit in plain-text a password that the user specified.
But if it's a randomly-generated new nonce, seems OK as a pragmatic middle-ground. Folks like us, who care, will log in and change it.
But if it's a randomly-generated new nonce, seems OK as a pragmatic middle-ground. Folks like us, who care, will log in and change it.
When a user is sent a password via email, unless that user is required to change eir password upon entering it, it is inherently less secure than sending a link.