In my view, for most applications, the upside is not really worth that downside. It got me thinking though, are there any clever solutions to do password reset without an email / social media account login / etc? Does anyone know of any good ones?
In my view, for most applications, the upside is not really worth that downside. It got me thinking though, are there any clever solutions to do password reset without an email / social media account login / etc? Does anyone know of any good ones?
This gets a little more tricky if you have an unexpired session but want to be able to change your password (which likely requires knowing the existing password), but a request from this logged in session to reset your password should be trustable (unless your "friends" have also stolen your unlocked device).
Similarly, if one or more of your "friends" requests a token / password reset of your acccount, the site should highlight that in a banner on every page you visit, to potentially give you warning to find better friends. (The process for replacing a friend on the site should probably require re-entering your password too, to stop someone that's hijacked your session from picking three sock puppet accounts as your new friends, and resetting your password that way).
Presumably if only one "friend" defects and attempts to reset your account you will be notified by the other two friends sending you unrequested reset tokens out of the blue
3 is kinda an arbitrary number, chosen to strike a balance between security and convenience. It was decided that getting 3 people to collude to erode the trust of the community was harder than intercepting an email so the solution was accepted as adding some additional amount of security.
Honestly a bigger flaw in this scheme is if one or more of your friends is no longer active or has forgotten their own password and cyclically is relying on you for backup. You can hedge against this a bit by adding more backups and requiring only some critical mass of tokens, but this does also increase the attack surface.
Another possibility is requiring a payment with a payment method they’ve used before and then credit their account with the amount. Forcing 3D secure on that transaction should cut down on fraudulent take overs; or at least shift the liability from you, somewhat.
If you have an app, you can also allow them to authorize the password reset from the app on a computer (or vice versa).
Lastly, you could just not have a password to forget. :)
In fact, the more I think about it, there's a paper I saw that can identify users solely by their mouse movements. If you maintained that kind of fingerprinting in game, you could simply ask the user to play a few rounds then offer to reset if they're from a typical IP address. Might work well for this particular website.
Assumes: - people are less likely to lose their PGP key, than random password to a random website. - people have PGP keys - PGP key doesn't contain email address (it does).
Anyway, it would be reliable, and it doesn't need giving third party online service access to all your online accounts.