Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
Security of Password Recovery
Message
 
 
À
30/12/2014 14:37:52
Information générale
Forum:
ASP.NET
Catégorie:
Autre
Versions des environnements
Environment:
VB 9.0
OS:
Windows Server 2012
Network:
Windows 2008 Server
Database:
MS SQL Server
Application:
Web
Divers
Thread ID:
01612857
Message ID:
01612862
Vues:
41
Did you have to make my job even more complex? :) (just kidding). Thank you. I will put this on my to-do list.

>One thing you can consider is limiting the number of password recovery attempts. For example, allow only 3 attempts per IP address per 24 hour period. Or if there are 3 unsuccessful attempts in a row, then that IP address is locked out permanently.
>
>This whole concept of automated password recovery is a bit scary. People tend to use a single e-mail address for many sites so if one site gets compromised, the harvested addresses can be tried on others.
>
>>I agree that the second approach (in your options) is misleading. So I will use the first approach. I don't see a real downside in terms of security.
>>Thank you.
>>
>>>I've seen this done two ways.
>>>
>>>- Return an error saying the email doesn't exist
>>>- Return a message that password reset instructions were sent. Personally, I don't like this method because the user can enter an invalid email address and think they're getting the reset instructions.
>>>
>>>
>>>>Hi,
>>>>
>>>>Speaking about security aspect of Password recovery. Regardless of the approach of resetting password (email password in plain text, or sending a link to reset a password), what if user enters an email that does not exist in the database? Is it ok to return to the user a message such as "Email not found"? In theory someone can check if this or that person has access to the site (by entering an email address) but do you think this may create a security breach?
"The creative process is nothing but a series of crises." Isaac Bashevis Singer
"My experience is that as soon as people are old enough to know better, they don't know anything at all." Oscar Wilde
"If a nation values anything more than freedom, it will lose its freedom; and the irony of it is that if it is comfort or money that it values more, it will lose that too." W.Somerset Maugham
Précédent
Répondre
Fil
Voir

Click here to load this message in the networking platform