Other than forgot-password, why use blobs at all? Only other rare use of blobs that I can think of is proxying users from one domain to another (single sign-on, session sharing etc.)
Why would a site use blobs for reporting?
Why would a site use blobs for reporting?
You cant replay attack the reset link once its used, it expires in 24 hours and so long as the 'secretkey' was sufficiently unique, you wouldnt be able to bruteforce or crack it.
All the php script needs to do is attempt to build a 'good' md5 hash and see if they match- if they do, let you input a new password to store.
Just use a random string as a primary key for a token table in a database and be done with it.