4 ms·
Account recovery emails should probably use one time tokens, meaning that after you click on the link once, the link becomes invalidated. This would largely sol
by dbla 12y ago
Account recovery emails should probably use one time tokens, meaning that after you click on the link once, the link becomes invalidated. This would largely solve the issue with point b.
- PythonicAlpha 12y agoNot only one time tokens, but with limited life-span. So after a while the token expires and is useless. This is a must for such a scheme.
- sturadnidge 12y agoBoth of these, plus a differentiator between 'current' and 'new' token requests - without that, it's an easy way to log people out of sites by simply knowing their email address. To the point about not always having access to email, it's a pretty simple denial of service vector.
- PythonicAlpha 12y agoCan you clarify, what you mean by "differentiator between current and new token requests"? Currently I don't exactly know which attack form you mean and how it could be prevented by such a "differentiator". (an example would be nice)