General Chat
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Codewalkers ForumsGeneralGeneral Chat

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Codewalkers Forums Sponsor:
  #1  
Old September 23rd, 2002, 12:33 PM
honcho's Avatar
honcho honcho is offline
Contributing User
Codewalkers Beginner (1000 - 1499 posts)
 
Join Date: Apr 2007
Location: Cape Cod
Posts: 1,347 honcho User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 3 h 52 m 2 sec
Reputation Power: 4
Handling lost passwords

I'm looking for ideas on how to handle lost passwords. Are there any schemes that really annoy you or any you have seen and thought "Wow, that's exactly how I hope I would implement it!"

The schemes I can think of are:
1. Use a preset question (e.g. Mother's maiden name) to verify identity and allow them to change the password.
2. Given correct email/username, email a new password.
3. Don't use anything automated - communication is done through email and changing is manually done by an admin.
4. Something else?

Reply With Quote
  #2  
Old September 23rd, 2002, 03:35 PM
notepad notepad is offline
Codewalkers Loyal (3000 - 3499 posts)
 
Join Date: Apr 2007
Location: Central, IL USA
Posts: 3,214 notepad User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 6
Send a message via AIM to notepad
RE: Handling lost passwords

i've always prefered the e-mail method myself. i never did provide an honest answer for the mothers maiden name type questions therefore i quickly forgot what i put for the answer..

Reply With Quote
  #3  
Old September 23rd, 2002, 04:43 PM
Matt Matt is offline
Contributing User
Codewalkers Specialist (4000 - 4499 posts)
 
Join Date: Apr 2007
Location: Florida
Posts: 4,158 Matt User rank is Private First Class (20 - 50 Reputation Level)Matt User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 4 h 12 m 16 sec
Reputation Power: 7
RE: Handling lost passwords

I prefer the send a random password via email. Then, require it is changed upon first login...

Reply With Quote
  #4  
Old September 23rd, 2002, 11:13 PM
blazin blazin is offline
Codewalkers Newbie (0 - 499 posts)
 
Join Date: Apr 2007
Location: Aurora, CO, USA
Posts: 24 blazin User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Send a message via ICQ to blazin Send a message via AIM to blazin
RE: Handling lost passwords

I agree with Matt. There should not be a way to extract a user's password from the database. It should be one-way encrypted in the database. If they forget, you email a new totally random password and set a flag that forces a password reset on next login.

If you have a retrievable password in the database (or text file, or whatever), someone will retrieve it, and it's not a situation you want to have.

Reply With Quote
  #5  
Old September 23rd, 2002, 11:31 PM
honcho's Avatar
honcho honcho is offline
Contributing User
Codewalkers Beginner (1000 - 1499 posts)
 
Join Date: Apr 2007
Location: Cape Cod
Posts: 1,347 honcho User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 3 h 52 m 2 sec
Reputation Power: 4
RE: Handling lost passwords

That's correct, I am using a one-way function (at least MySQL's PASSWORD function better be one-way). I think the three scenarios I mentioned all confrom to this.

Thanks for your responses. The only problem with my system is that I don't require an email address (due to business reasons and not anything technical), so emailing a new password might not work all the time.

Reply With Quote
Reply

Viewing: Codewalkers ForumsGeneralGeneral Chat > Handling lost passwords


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump




 Free IT White Papers!
 
How to Present Effectively Online
This white paper offers practical and actionable advice on the key steps that any presenter should consider as they plan and execute a Webinar or online meeting.

Request Your Free Technology Downloads!
 
Open Source Security Myths
Open Source Software (OSS) is computer software whose source code is available to the general public with relaxed or non-existent intellectual property restrictions (or arrangement such as the public domain), and is usually developed with the input of many contributors.

Request Your Free Technology Downloads!
 
Power and Cooling Capacity Management for Data Centers
This paper describes the principles for achieving power and cooling capacity management.

Request Your Free Technology Downloads!
 
Scalable, Fault-Tolerant NAS for Oracle - The Next Generation
For several years NAS has been evolving as a storage alternative for Oracle databases, and for good reason: NAS is quite often the simplest, most cost-effective storage approach for Oracle. Learn about the benefits that HP's approach to scalable NAS brings to Oracle environments in this comprehensive white paper.

Request Your Free Technology Downloads!
 
Understanding Web Application Security Challenges
This white paper discusses many common threats and preventive measures for Web application security, and explains what you can do to help protect your organization.

Request Your Free Technology Downloads!
 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 




© 2003-2009 by Developer Shed. All rights reserved. DS Cluster 1 Hosted by Hostway
For more Enterprise Application Development news, visit eWeek