Re: best practices for user friendly and secure forgotten password resolution

Greg Austin <[email protected]>
Newsgroups gmane.org.user-groups.bay-area
Message-ID <[email protected]>
If no one uses the systemor gets so angry at it that they hate it 
then the entire app proves worthless anyhow. I would err on the side  
of usability, dealing with security in other waysthat is, given an  
absolute need for security in the first place. Banks run into this  
problem frequently; in that case, an actual human must be called to  
resent the account.

High-security sites may consider finger-printing clients.

However, if security of a game site is in question, who cares?

In such a case, I would establish other means to ID end-users. Names  
are a start. Names of favorite pets, etc.

Regardless, security should not get in the way of user-centered  
design, or in any way building the app, as a car is not built around  
the ignition key.


On Aug 21, 2009, at 2:29 PM, Laura Malone wrote:

> Hi all,
> The use case I'm asking for input on is this: The user has forgotten  
> their password and types in an email address that is not in our  
> system. Currently we tell them that we don't have that email address  
> in our system and to try another or register. However, we have been  
> mandated to address the security issues around this approach.  
> Apparently, by telling the user we don't have that email address in  
> their system allows a hacker/attacher to keep trying other email  
> addresses until they get a match.
> So in other words, there is a conflict between the ease of use in  
> telling a user who has forgotten their password that we don't have  
> their email address in our system vs. the potential breech of  
> security that this messaging apparently invites.
> My question is, have you resolved this conflict in your website, and  
> if so, how?
> Thanks for any insight,
> Laur Malone
> _______________________________________________
> This is the BayCHI Discussions mailing list, [email protected]
> To change your subscription options, or to unsubscribe, visit http://baychi.org/mailman/listinfo/discussions

Greg Austin
[email protected]
_______________________________________________
This is the BayCHI Discussions mailing list, [email protected]
To change your subscription options, or to unsubscribe, visit http://baychi.org/mailman/listinfo/discussions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.