Re: best practices for user friendly and secure forgotten password resolution
Jeff Lowe <[email protected]>
| Newsgroups | gmane.org.user-groups.bay-area |
|---|---|
| Message-ID | <[email protected]> |
My company ran into the same issue when security auditors recommended that we stick with a generic auth failure message so not to tip off hackers that the account actually exists. We just use the generic message. I've seen sites get around this by asking users to answer a few security questions that they set up when creating their account. However, that approach is not foolproof either. There was a well- publicized breach of Sarah Palin's Yahoo! email account when a hacker guessed the easy answers she created for her security questions. Jeff On Aug 21, 2009, at 2:29 PM, Laura Malone wrote: > Hi all, > The use case I'm asking for input on is this: The user has forgotten > their password and types in an email address that is not in our > system. Currently we tell them that we don't have that email address > in our system and to try another or register. However, we have been > mandated to address the security issues around this approach. > Apparently, by telling the user we don't have that email address in > their system allows a hacker/attacher to keep trying other email > addresses until they get a match. > So in other words, there is a conflict between the ease of use in > telling a user who has forgotten their password that we don't have > their email address in our system vs. the potential breech of > security that this messaging apparently invites. > My question is, have you resolved this conflict in your website, and > if so, how? > Thanks for any insight, > Laur Malone > _______________________________________________ > This is the BayCHI Discussions mailing list, [email protected] > To change your subscription options, or to unsubscribe, visit http://baychi.org/mailman/listinfo/discussions _______________________________________________ This is the BayCHI Discussions mailing list, [email protected] To change your subscription options, or to unsubscribe, visit http://baychi.org/mailman/listinfo/discussions