4 ms·
> asking for the other user's password What? Why would the other user ever provide their password to this user?
by robryk 9y ago
> asking for the other user's password
What? Why would the other user ever provide their password to this user?
- techdragon 9y agoHow about an Administration interface that allows you to set a password to a known value for the user to use so they can log back into their account. So the helpful support person can now go "Your password is now 'foobar' and you will be asked to pick a new one when you login."
- desas 9y agoThat doesn't sound like a safe way of resetting passwords. You should supply them a token they can use to set their own password. Your employees should not know your users passwords.
- zaarn 9y agoIn a corporation, this is totally okay as long as the reset password is safe or the account is locked from external access until the password has been changed. The employee should of course change their password and that should be enforced policy, the admin shouldn't know user passwords. Tokens work too but it's a bit of an overhead, especially in smaller SMB where the admin is probably just across the corridor or atleast in the same building.
- will_hughes 9y agoThe token is the new one-time password that must be reset upon login.
- sdoering 9y agoExactly that. I use this feature as an Admin relatively often in Adobe Analytics. I never am able to know the "real" password a user provides on first login after reset. A one time password is nothing but a token - maybe not ideally named.
- jrockway 9y agoWhy would you use input type=password for that?
- ben_w 9y agoBecause it is, in fact, a password.
- deleted 9y ago[deleted]
- SamBam 9y agoYou're creating a secret token. Both the administrator and the browser should be made aware of this. The administrator, so that they don't send it to the user via an unsecure method (Tweet it publicly), the browser so that it shows warnings if the site is somehow served without ssl or is compromised. If it's something like a password, it should be treated like a password. Why shouldn't you use type=password for that?
- robryk 9y agoWhy not let the administrative interface generate the temporary password and show it?