Re: Handling forgotten passwords

Tech-Archive recommends: Fix windows errors by optimizing your registry



On Sun, 11 Jun 2006 22:23:39 -0500, Showjumper wrote:

A question regarding forgotten passwords - As i understand it, it is best
and most secure to use a 1 way hash+salt to store passwwords, and then if
the user has forgotten the password, generate a new password and then email
to them. What i dont understand how that is any more secure than using a
reversible encryption to store the password which would allow decrypting and
then emailing it to the user. In both cases, an email is still sent w/ a
password.

Why email them their password? They already entered it, they know what it
is.

The thing to keep in mind is that if someone breaks into your server (not
something most people want to think about), can they get your users data
somehow?
.



Relevant Pages

  • Handling forgotten passwords
    ... and most secure to use a 1 way hash+salt to store passwwords, ... What i dont understand how that is any more secure than using a ... then emailing it to the user. ... Ashok ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Handling forgotten passwords
    ... Retrieving a password/Generating a new password ... Or code that can generate a new password is a more secure ... more secure option is to have one or more secret question and answer pairs ... and most secure to use a 1 way hash+salt to store passwwords, ...
    (microsoft.public.dotnet.framework.aspnet)
  • RE: [PHP] Site Security
    ... Users must log in to use the site and the users data is held in the ... > Users table of the MySQL database. ... > need to make sure it is 110% secure against hacks etc. ... a security audit from a company called @stake. ...
    (php.general)
  • Site Security
    ... I have created a site that allows users to schedule staff, make appointments ... Users must log in to use the site and the users data is held in the ... secure as possible, I have no experience on this aspect of web development. ...
    (php.general)
  • Re: Second try with Beverage Antenna in WW2
    ... > What he did was secure one end of the tubing to a vise on a workbench ... > in his garage, secured the other end somehow (don't remember exactly ...
    (rec.radio.amateur.antenna)