4 ms·
A better way for Hacker News to handle password resets is to send the original email address associated with the account an email containing a one-time, expirin
by marcinw 16y ago
A better way for Hacker News to handle password resets is to send the original email address associated with the account an email containing a one-time, expiring link allowing the user to change their password from. Otherwise, your password would remain unchanged.
- kvs 16y agoWhy is this better than current approach? Is it because the current password remain unchanged until the user click on the link to reset part?
- theandym 16y agoExactly. It allows people to easily reset their passwords if they've forgotten them while reducing their need to update their password if someone accidentally/maliciously attempts a reset.
- AdamGibbins 16y agoI think a better method is to send a new password but continue to allow the users old password until they first login with their new password at which point the old is erased and only the new is valid. It removes that extra step and is in turn simpler for the user. Rather than sending them this weird long URL - not such a problem with HN but with other less-technical sites I suspect this causes some confusion the first time someone experiences one.
- marcinw 16y agoThis approach would introduce more complexity than it's worth, in addition to being less secure. Instead of just one password that can be used to login to your account, you now have two valid passwords.
- AdamGibbins 16y agoI'm not convinced its less secure, the old password invalidates the second you login using your new password. This beats the current method which just locks you out (I believe anyhow? I've not tried it personally). Its along the same lines as the URL method but without the added confusion for the user. Complexity for the developer perhaps, although you could also use the same branch of code to give you the ability to force password changes etc. And I think the added dev work is worth it for the user. Time for some A/B testing perhaps.
- marcinw 16y agoAt any moment, you can have two valid passwords used to access your account. Do all the A/B testing you want, this is NOT how you handle password resets.* * Note that even my proposed solution is not the best way to handle password resets. Trust me on this, I've seen way too many applications do this wrong which have resulted in ability to compromise arbitrary users' accounts.
- AdamGibbins 16y agoPlease explain why, simply saying its not doesn't really add anything to the conversation nor convince me otherwise. I'm not sure I understand why not. With your common URL method theres still two ways to authenticate, just as there is mine. They could "guess" the reset key just as easy as they could "guess" the new generated password. You'd have both expiring so the period for attack is minimal. Please explain how my method is any less secure? Perhaps I'm missing some key security principles (likely), in which case please guide them to me. But just repeating that its less secure without backing up with some logic really doesn't convince me nor teach me anything. Edit: I forgot to mention apologies - I'm not saying the password should remain as the one that was emailed. You can and should force people to change it upon the first login with their new password. Perhaps thats where the security confusion was. People storing passwords in email is poor, theres no debate there. Though yes, at a second thought this puts an extra step in for the user - A/B testing would be of use here.
- marcinw 16y ago
- ra 16y agoYes, that is a much better way to do it. Also the resetting user should be asked to provide their email address rather than the public forum username which is easily scrapped.