tulpa,
@tulpa@fosstodon.org avatar

So many password reset processes are trivially easy to abuse or defeat.

dusnm,
@dusnm@fosstodon.org avatar

@tulpa How would you go about verifying the identity of a person who requested a password reset?

tulpa,
@tulpa@fosstodon.org avatar

@dusnm Personally, I wouldn't. It's too hard.

dusnm,
@dusnm@fosstodon.org avatar

@tulpa "I wouldn't" doesn't cut it. People often forget passwords. It's paramount there exist some mechanism to reset it.

The main weakness of the established method (just send an email) is that people reuse passwords.

A better approach is requiring 2FA be turned on at all times. So, even after confirming access to the email address, you must now additionally confirm ownership by way of using TOTP codes.

I think this works well enough.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • kavyap
  • normalnudes
  • everett
  • DreamBathrooms
  • ethstaker
  • magazineikmin
  • thenastyranch
  • Youngstown
  • GTA5RPClips
  • slotface
  • khanakhh
  • vwfavf
  • rosin
  • mdbf
  • provamag3
  • Leos
  • Durango
  • tacticalgear
  • InstantRegret
  • cubers
  • osvaldo12
  • ngwrru68w68
  • anitta
  • tester
  • modclub
  • cisconetworking
  • megavids
  • JUstTest
  • All magazines