IWETHEY v. 0.3.0 | TODO
1,095 registered users | 1 active user | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New 16) Storing them encrypted with a "reset my password" featur
16) Storing them encrypted with a "reset my password" feature that emails a new random password reset URL. That URL times-out after 24-36 hours or gets removed if another request is made during the timeout period. If the URL never gets used, the reset never happens, but if it does get used, the password is reset by the requestor on that page. Also, limit the number of requests per day, to evade a Mail DoS.

I hate reminder based password crap, never want someone to have to service my own problems. Let me take care of mine.
--
[link|mailto:greg@gregfolkert.net|greg],
[link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @ iwethey
No matter how much Microsoft supporters whine about how Linux and other operating systems have just as many bugs as their operating systems do, the bottom line is that the serious, gut-wrenching problems happen on Windows, not on Linux, not on Mac OS. -- [link|http://www.eweek.com/article2/0,1759,1622086,00.asp|source]
Here is an example: [link|http://www.greymagic.com/security/advisories/gm001-ie/|Executing arbitrary commands without Active Scripting or ActiveX when using Windows]
Collapse Edited by folkert Nov. 30, 2004, 06:38:09 PM EST
4) Storing them encrypted with a "reset my password" feature
4) Storing them encrypted with a "reset my password" feature that emails a new random password reset URL. That URL times-out after 24-36 hours or gets removed if another request is made during the timeout period. If the URL never gets used, the reset never happens, but if it does get used, the password is reset by the requestor on that page.

I hate reminder based password crap, never want someone to have to service my own problems. Let me take care of mine.
--
[link|mailto:greg@gregfolkert.net|greg],
[link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @ iwethey
No matter how much Microsoft supporters whine about how Linux and other operating systems have just as many bugs as their operating systems do, the bottom line is that the serious, gut-wrenching problems happen on Windows, not on Linux, not on Mac OS. -- [link|http://www.eweek.com/article2/0,1759,1622086,00.asp|source]
Here is an example: [link|http://www.greymagic.com/security/advisories/gm001-ie/|Executing arbitrary commands without Active Scripting or ActiveX when using Windows]
     zIWT meta: Which is better: - (admin) - (66)
         3) -NT - (mmoffitt)
         1) - (jb4) - (3)
             Not for long, at least... -NT - (admin) - (2)
                 Is that a threat?!? -NT - (jb4) - (1)
                     You should know by now... - (admin)
         3, with verification - (Arkadiy) - (29)
             Seconded. -NT - (Yendor)
             NO - (FuManChu) - (27)
                 Er, buh? - (admin) - (3)
                     That's enough of a detriment not to warrant the risk IMO -NT - (FuManChu) - (2)
                         ? -NT - (admin) - (1)
                             ?? -NT - (drewk)
                 Yeah - (Yendor) - (11)
                     How is that insecure? - (FuManChu) - (2)
                         You're unclear on this. - (admin) - (1)
                             See below. -NT - (FuManChu)
                     You only need one field labeled "Hint" - (tuberculosis) - (7)
                         Sure... - (Yendor) - (6)
                             Bah. - (admin)
                             Not quite - (FuManChu) - (4)
                                 And my point is... - (Yendor) - (3)
                                     I have a standard formula I use for passwords. - (folkert) - (2)
                                         I also have a standard formula - (daemon) - (1)
                                             Ding, Ding, Ding. - (folkert)
                 It's only insecure if the user is allowed to proceed - (imric) - (10)
                     Bah. Risk is the issue. - (FuManChu) - (9)
                         So what's YOUR suggestion? -NT - (admin) - (4)
                             Unfortunately for you #1 ;) - (FuManChu) - (3)
                                 WTF? - (admin) - (2)
                                     Sorry. You're right. I didn't read carefully. - (FuManChu) - (1)
                                         So how does that change your answer? - (admin)
                         Same risk than we have now during login. - (imric) - (2)
                             Same outcome, different risk--the attack surface has doubled -NT - (FuManChu)
                             Not mine. - (CRConrad)
                         Can we please weight the risks - (Arkadiy)
         3) with some safeguards? - (Another Scott)
         4) WikiWay: everything wide open ... muuuaaaahahahahahaha -NT - (drewk) - (1)
             Shaddap wid' yer shaddin' ap... -NT - (admin)
         3 with a "what is your dog's name?" thingie -NT - (Silverlock)
         I'll join Ark, Scott(2), Don(Silverback), and YendorMike: 3+ - (CRConrad) - (2)
             <raises hand> on that last bit. :-) -NT - (Another Scott)
             Aye - 3) with - (imric)
         Another few options: - (admin) - (9)
             I'd rather not vote on solutions until we discuss risks - (FuManChu) - (8)
                 Re: I'd rather not vote on solutions until we discuss risks - (admin) - (7)
                     Okay, start with costs of current proposals - (FuManChu) - (3)
                         Missed the point. :-) - (admin) - (2)
                             Understood, but you're use case #1 - (FuManChu) - (1)
                                 I can do private keys... - (folkert)
                     What do you want the software to do? - (Another Scott) - (2)
                         Nope, wrong - (drewk) - (1)
                             Yes, a *good* challenge question would be needed. - (Another Scott)
         how about 4, the way we do it now - (daemon) - (3)
             Which is? - (Another Scott)
             And what would that be? - (admin) - (1)
                 the way it works now - (daemon)
         How about 5... - (jb4)
         16) Storing them encrypted with a "reset my password" featur - (folkert)
         A variation on 2) - (altmann)
         3), with a question 1st. -NT - (broomberg)
         3 with a proviso - (ChrisR) - (1)
             I like that! -NT - (Arkadiy)
         3. Puts the onus of keeping valid email address on user. -NT - (a6l6e6x)
         3 -NT - (pwhysall)
         6. - (static)
         "zIWT meta: Which is better:" Voting/Ratification (new thread) - (folkert)

I signed a contract that said so.
64 ms