Beefy Boxes and Bandwidth Generously Provided by pair Networks
Problems? Is your data what you think it is?
 
PerlMonks  

Re^3: It's been ten years ...

by haj (Curate)
on Jul 29, 2019 at 23:22 UTC ( #11103604=note: print w/replies, xml ) Need Help??


in reply to Re^2: It's been ten years ...
in thread It's been ten years ...

Lanx writes:
This would imply adjusting the What's my password? mechanism too.

Yes, of course. You can improve easily by creating a fresh random password and mailing that to the user, and then store it encrypted. After all, they forgot their password, right?

This is still bad security practice, though, as plain text email isn't actually secure. With a bit more effort you can get a decent self-service password reset function. This has been done before, it isn't rocket surgery.

Replies are listed 'Best First'.
Re^4: It's been ten years ...
by tinita (Parson) on Jul 30, 2019 at 09:26 UTC
    Yes, of course. You can improve easily by creating a fresh random password and mailing that to the user, and then store it encrypted.
    No, please no!

    (I know many websites do this.)
    So everone claiming "I am user X and I forgot my password" can now reset my password, and I am locked out and have to check my email.

    The minimum password procedure should be: store an intermediate token, send the user a link with that token and then let them enter their new password. And that means, we need a new endpoint *and* a new database table probably. So it's not that trivial.
      I didn't use a token but a one way URL which is timing out after an hour.

      Needed two extra tables IIRC...

      To be able to integrate this here one would need godly powers or an offline development environment.

      Cheers Rolf
      (addicted to the Perl Programming Language :)
      Wikisyntax for the Monastery FootballPerl is like chess, only without the dice

Re^4: It's been ten years ...
by LanX (Cardinal) on Jul 30, 2019 at 00:32 UTC
    > With a bit more effort you can get a decent self-service password reset function. This has been done before, it isn't rocket surgery.

    I know, "a decent self-service password reset function" was my first task at my current job.

    Good luck integrating it here!

    Cheers Rolf
    (addicted to the Perl Programming Language :)
    Wikisyntax for the Monastery FootballPerl is like chess, only without the dice

Log In?
Username:
Password:

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://11103604]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others surveying the Monastery: (4)
As of 2020-10-27 07:12 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?
    My favourite web site is:












    Results (256 votes). Check out past polls.

    Notices?