4 ms·
Sorry for not explaining, maybe the following will convince you. When an application generates a password, about how long/secure are these passwords? (on avera
by marcinw 16y ago
Sorry for not explaining, maybe the following will convince you. When an application generates a password, about how long/secure are these passwords? (on average, and remember, we're staying user friendly...) Probably about 8-10 characters, alphanumeric, MAYBE a special character.
Now let's say you had to only create a link as I proposed. The length of the "secure" token can be as long as you want! Because the URL is not entered manually, you don't have to worry about being so "user-friendly" (as long as your url doesn't break in mail clients..)
If you fed a secure PRNG to an HMAC-SHA256/512 hash or a UUID... These values would be much, MUCH harder to guess than any password you could generate for your user. As a result, the following is not true:
> They could "guess" the reset key just as easy as they could "guess" the new generated password.
You bring up a good point about the password delivery over cleartext (though HN doesn't use SSL anyway, I didn't consider it at the time of posting). On a side note, does HN even have account lockout?