3 ms·
Could you explain why that's bad for someone who knows nothing about security? Where should the password reset token be?
by ghostbrainalpha 6y ago
Could you explain why that's bad for someone who knows nothing about security?
Where should the password reset token be?
- dewey 6y agoIn an email sent to the address linked to the account.
- Jtsummers 6y agoIt should’ve been sent via email to the registered email address. That lets the account owner reject it (I didn’t request a password reset!) or use it.
- sebmellen 6y agoThe token should only be accessible to the user requesting the password reset, meaning that it would be sent via email (this is the standard password reset flow). The flaw here is that anyone, even if they did not control the email of the user, could reset the password, because the reset token was returned in the browser, where anyone could see it. Essentially, just by knowing someone's email (not having control over it), you could reset their password.
- ghostbrainalpha 6y agoYou did a really great job breaking that down! Thank you!