Re: best practices for user friendly and secure forgotten password resolution

Brian Krause <[email protected]>
Newsgroups gmane.org.user-groups.bay-area
Message-ID <[email protected]>
Laura--

Showing the e-mail address they typed in so they can at least check it  
again for typos will help.  A lot of systems just have a generic thank- 
you that doesn't repeat what is typed so people have no idea that they  
got it wrong.  Also, it's good to make it clear how enter the correct  
address, ideally right on the same page.  "We just sent instructions  
to [email protected].  If that's not what you meant to type, enter the  
correct address below and click 'Send.'"

(Through this design of returning to the page where the e-mail address  
is entered, you could also invite users to enter other possible  
addresses if you are afraid they might not remember which address it  
is they used to sign up for your service.  "If there is another  
address that might be associated with your account.")

But if you want to catch the case where users don't know which address  
they have used, you can send instructions to every address entered,  
whether you have it on file or not.  "Someone entered your address,  
but this isn't an address we have on file for an existing account.  Is  
there some other address you might have used?"  This way, you are not  
giving that information to any hacker on the web, but only to the  
person who can receive e-mail sent to the address, presumably a  
genuinely confused customer.  They don't get the information quite as  
quickly, but at least they're not going to wait an hour until they  
realize they gave the wrong address.

--Brian


On Aug 21, 2009, at 3:11 PM, Jeff Lowe wrote:

> My company ran into the same issue when security auditors  
> recommended that we stick with a generic auth failure message so not  
> to tip off hackers that the account actually exists. We just use the  
> generic message.
>
> I've seen sites get around this by asking users to answer a few  
> security questions that they set up when creating their account.  
> However, that approach is not foolproof either. There was a well- 
> publicized breach of Sarah Palin's Yahoo! email account when a  
> hacker guessed the easy answers she created for her security  
> questions.
>
> Jeff
>
> On Aug 21, 2009, at 2:29 PM, Laura Malone wrote:
>
>> Hi all,
>> The use case I'm asking for input on is this: The user has  
>> forgotten their password and types in an email address that is not  
>> in our system. Currently we tell them that we don't have that email  
>> address in our system and to try another or register. However, we  
>> have been mandated to address the security issues around this  
>> approach. Apparently, by telling the user we don't have that email  
>> address in their system allows a hacker/attacher to keep trying  
>> other email addresses until they get a match.
>> So in other words, there is a conflict between the ease of use in  
>> telling a user who has forgotten their password that we don't have  
>> their email address in our system vs. the potential breech of  
>> security that this messaging apparently invites.
>> My question is, have you resolved this conflict in your website,  
>> and if so, how?
>> Thanks for any insight,
>> Laur Malone
>> _______________________________________________
>> This is the BayCHI Discussions mailing list, [email protected]
>> To change your subscription options, or to unsubscribe, visit http://baychi.org/mailman/listinfo/discussions
> _______________________________________________
> This is the BayCHI Discussions mailing list, [email protected]
> To change your subscription options, or to unsubscribe, visit http://baychi.org/mailman/listinfo/discussions
_______________________________________________
This is the BayCHI Discussions mailing list, [email protected]
To change your subscription options, or to unsubscribe, visit http://baychi.org/mailman/listinfo/discussions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.