Ask HN: I just got a new password by email from info[at]ycombinator.com
Has this happened to anyone else?
And is it possible to get the IP that requested this?
thanks
Has this happened to anyone else?
And is it possible to get the IP that requested this?
thanks
I don't think I would worry about it too much unless I started getting lots of these emails.
It removes that extra step and is in turn simpler for the user. Rather than sending them this weird long URL - not such a problem with HN but with other less-technical sites I suspect this causes some confusion the first time someone experiences one.
Complexity for the developer perhaps, although you could also use the same branch of code to give you the ability to force password changes etc. And I think the added dev work is worth it for the user.
Time for some A/B testing perhaps.
* Note that even my proposed solution is not the best way to handle password resets. Trust me on this, I've seen way too many applications do this wrong which have resulted in ability to compromise arbitrary users' accounts.
I'm not sure I understand why not. With your common URL method theres still two ways to authenticate, just as there is mine. They could "guess" the reset key just as easy as they could "guess" the new generated password. You'd have both expiring so the period for attack is minimal.
Please explain how my method is any less secure? Perhaps I'm missing some key security principles (likely), in which case please guide them to me. But just repeating that its less secure without backing up with some logic really doesn't convince me nor teach me anything.
Edit: I forgot to mention apologies - I'm not saying the password should remain as the one that was emailed. You can and should force people to change it upon the first login with their new password. Perhaps thats where the security confusion was. People storing passwords in email is poor, theres no debate there. Though yes, at a second thought this puts an extra step in for the user - A/B testing would be of use here.
Now let's say you had to only create a link as I proposed. The length of the "secure" token can be as long as you want! Because the URL is not entered manually, you don't have to worry about being so "user-friendly" (as long as your url doesn't break in mail clients..)
If you fed a secure PRNG to an HMAC-SHA256/512 hash or a UUID... These values would be much, MUCH harder to guess than any password you could generate for your user. As a result, the following is not true:
> They could "guess" the reset key just as easy as they could "guess" the new generated password.
You bring up a good point about the password delivery over cleartext (though HN doesn't use SSL anyway, I didn't consider it at the time of posting). On a side note, does HN even have account lockout?
Also the resetting user should be asked to provide their email address rather than the public forum username which is easily scrapped.
Btw, just send you a new one.
oops