4 ms·
I use BCrypt, and do the following: 1. replace their current hash with "LOCKED", plus some random noise. 2. generate a random string, and store the hash in a
by kaffeinecoma 15y ago
I use BCrypt, and do the following:
1. replace their current hash with "LOCKED", plus some random noise.
2. generate a random string, and store the hash in a "forcedResetToken" field for the user.
3. email them a URL, part of which is the token.
4. when the link is activated, I look up the user account by
the hash of the token, force them to choose a new pw, and remove the forcedResetToken.
That's the approach I take in my Wicket Quickstarter project (http://armhold.com/store http://armhold.com/store).
Based on other comments I'm seeing, I'm now planning to also add an expiration of the token (say 24 hours or something).
- halayli 15y agoSo if I know a user's email I can lock their account by just triggering a reset password.
- ra 15y agoYeah brute force lockout is a destructive attack. A better lock-out approach is to disable logins for a period of time (say 1 minute)... i.e. as someone said above, you don't want to destroy the old password in case the reset was requested by someone else.