3 ms·
>This is one I always struggled to understand. If email is compromised, the attacker can request and immediately intercept a password reset anyway. Not really
by blkhawk 12y ago
>This is one I always struggled to understand. If email is compromised, the attacker can request and immediately intercept a password reset anyway.
Not really the main issue - if you always send the password the Thief controlling the email does not even need to reset the password. he can get in without leaving any trace at any time. It also allows the collection of all the Passwords from all the users in bulk. And if your users are reusing their passwords everything else is open too.
Sending the Password is just a stupid policy. Its up there with restrictive Password requirements and Server-side unhashed Password storage.