Re: Forgotten password
- From: Jerry Stuckle <jstucklex@xxxxxxxxxxxxx>
- Date: Sun, 30 Dec 2007 16:28:59 -0500
C. (http://symcbean.blogspot.com/) wrote:
On 29 Dec, 13:50, Anthony Levensalor <anth...@xxxxxxxxxxxxxxxxxxx>
wrote:
rf said:
"twomt" <no-re...@xxxxxxxxxxxxxx> wrote in messageNo, that would be stupid. If someone has a password with me, as in an
news:fl5ea5$d1u$1@xxxxxxxxxxx
Hello,To where would you email him the new password? What if I enter my email
are there any tutorials/guides out there that explain how to handle this
subject?
I was thinking of having a member enter his username and email, after
which I then email him a new password.
address, do you email his new password to me?
--
Richard.
account at one of my sites, I already have their email in a database. I
mail the new password to that address, and done is done.
~A!
--
Anthony Levensalor
anth...@xxxxxxxxxxxxxxxxxxx
Only two things are infinite, the universe and human stupidity,
and I'm not sure about the former. - Albert Einstein
1) that's inflexible - you are expecting the user to know 2 out of
three facts
Which is why I only require the user id.
2) it provides a way for a third party to carry out a denial of
service attack against your users.
Not at all. At most the user will get one email per day. The system won't send it more often than that.
If you look at existing systems the more sensible ones send out a URL
with a single use visa in the the query part allowing the user to
access the site without presenting their login credentials.
C.
True. But just sending the password once works, also. Not as secure, but often times it's secure enough.
--
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@xxxxxxxxxxxxx
==================
.
- References:
- Forgotten password
- From: twomt
- Re: Forgotten password
- From: rf
- Re: Forgotten password
- From: Anthony Levensalor
- Re: Forgotten password
- From: C. (http://symcbean.blogspot.com/)
- Forgotten password
- Prev by Date: imagetruecolortopalette returns a max of 128 colors
- Next by Date: project takeover/need help clearing easy bugs
- Previous by thread: Re: Forgotten password
- Next by thread: Re: Forgotten password
- Index(es):
Relevant Pages
|