Hello and welcome to our community! Is this your first visit?
Register
Enjoy an ad free experience by logging in. Not a member yet? Register.
Results 1 to 3 of 3

Thread: Is this secure

  1. #1
    Senior Coder timgolding's Avatar
    Join Date
    Aug 2006
    Location
    Southampton
    Posts
    1,519
    Thanks
    114
    Thanked 110 Times in 109 Posts

    Is this secure

    Alot of web sites offer the chance to reset your password. If you've forgotten your password you can say you've forgotten your password. Then the site usually does one of the following:
    • Send the password via email
    • Reset the password and send the reset password via email


    Can emails not be sniffed for text such as the text of the password in the email. How can you encrypt the email? Is there anything you can do?
    You can not say you know how to do something, until you can teach it to someone else.

  • #2
    Supreme Master coder! _Aerospace_Eng_'s Avatar
    Join Date
    Dec 2004
    Location
    In a place far, far away...
    Posts
    19,291
    Thanks
    2
    Thanked 1,043 Times in 1,019 Posts
    What I would do is give them a temporary link that allows them to reset their password. They would have to use the site's interface to reset it rather than have it in an email. Secret questions are often good ways to make sure its that person changing their password.
    ||||If you are getting paid to do a job, don't ask for help on it!||||

  • #3
    Senior Coder timgolding's Avatar
    Join Date
    Aug 2006
    Location
    Southampton
    Posts
    1,519
    Thanks
    114
    Thanked 110 Times in 109 Posts
    yes good idea maybe a link with a hashed get query string such as

    index.php?password_reset=32e09232d75641f6dbdf2552b3e3319b

    I wonder if it would be a good idea including a timeout to stop the reset being valid after a certain time period.

    I guess when they click the link they get directed to a page thats asks their secret question then if correct reset the password otherwise? - Destroy them!!
    You can not say you know how to do something, until you can teach it to someone else.


  •  

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •