Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 09-01-2009, 05:38 PM   #1 (permalink)
Right Off the Assembly Line
 
Join Date: Jan 2009
Posts: 1
Post Which approach of these two is better?


I'm in dilemma to use one of the options for forgot my password. Please list out the reasons to support which one is better.

1.The user is emailed a link to a page where he can reset his password if he or someone uses the forgot my password option.

2. The user is emailed the old password if he or someone uses the forgot my password option.

I would like to know which do u think is better in all aspects and why?

I hope to see some good replies ASAP.
ralphigo is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 09-01-2009, 06:41 PM   #2 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,493
Default Re: Which approach of these two is better?

In my application, this is how I do it:

1. If a user requests resetting of password, he is asked to enter his username/email/both. An email is sent to that user to ask if he really had requested the password reset.
2. If the user confirms that he has requested the password reset, then the new password is generated and emailed to the user.

Note that password is not yet changed in step 1 because it could be some other person trying to reset somebody's account.

Important:
If you are emailing the old password, it means that the application is not secure. Passwords can be stolen by anybody who has access to the database.

If you are desiging some web application/website, I would advise you to read more on security.

The best way to store authentication details is to use salts and hash of salted passwords. Simply hashes is also not that secure.
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता
victor_rambo is offline  
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows AntiSpyware (Beta): Analysis Approach and Categories digen Software Q&A 1 17-04-2005 09:38 PM

 
Latest Threads
- by Charan
- by Charan

Advertisement




All times are GMT +5.5. The time now is 03:35 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2