4 ms·
You need to worry about users who have other people maliciously requesting resets just to bother them. A password reset link in email is the more easily ignored
by trotsky 15y ago
You need to worry about users who have other people maliciously requesting resets just to bother them. A password reset link in email is the more easily ignored. If you send a new password, you need to make sure you still accept the old one in case it wasn't them who requested the reset. You'd also want/need to time out the 2nd "reset" password after a short period, as you don't want someone who gains access to their email account to be able to use it sometime in the future (possibly long after they've lost access to the email account). Long story short - use the reset link, there are good reasons why it's the widely used choice.
- edanm 15y agoHow common is the resetting someone's password to annoy them? I know it's a very common rationale for sending reset links, but I'm trying to remember if I've ever heard of it actually happening for real, and drawing a blank.
- trotsky 15y agoI'm sure it's service dependent, with some services the frequency would likely be essentially 0, but some services like popular online games you'd see it happen widely the first day you allowed it. The problem is, one person does this you pretty much have to change your code immediately if you disable an old password. And while I focused on the malicious, don't discount the accidental - my gmail routinely gets sent email meant for people who couldn't enter their own email address correctly when signing up for various things. If out of the blue a customer can't use their password and has to go find a new one to enter they aren't going to be too impressed even if it doesn't happen again.
- clarkbox 15y agoi get about one bogus password reset request every two months for my gmail account...