What happened to the Messenger Plus! forums on msghelp.net?
Shoutbox » MsgHelp Archive » Messenger Plus! for Live Messenger » WLM Plus! Help » can't access my msgplus account

can't access my msgplus account
Author: Message:
CookieRevised
Elite Member
*****

Avatar

Posts: 15519
Reputation: 173
– / Male / Flag
Joined: Jul 2003
Status: Away
RE: can't access my msgplus account
quote:
Originally posted by V@no
after user submitted their email address, send a link (with some unique hash/id, which could be a MD5 hash from old email + new email, granted it would require an aditional field in the users database). The user then will require visit that address where they can change their password.
(y)... although it shouldn't be a hash of the old and new email address because that can easily be guessed, calculated and abused too. It should be like in any other 'forgot pwd' system: just a random GUID, impossble to guess, and which expires after a very short time. Otherwise it will not solve your point B either.

And as for your point A: that can't be solved like that in a secure way. The user must always have access to the email address he provided when he signed up, otherwise he is out of luck. The ability to enter an alternative email address to send the link to, without any further validation, is a very massive 'no-no' and an open door for hacking. Stuff like this is usually solved by setting an alternative email address in your user profile _after_ you have successfully signed in (thus with the correct password); it is never asked, and should never be asked when you click a "forget pwd" link. The user should be able to select the option to send the link to his lternative email though, provided he set one up before.

Either way, yes, that "forget pwd" system should indeed be revised too.

This post was edited on 02-25-2011 at 08:18 PM by CookieRevised.
.-= A 'frrrrrrrituurrr' for Wacky =-.
02-25-2011 08:16 PM
Profile PM Find Quote Report
« Next Oldest Return to Top Next Newest »

Messages In This Thread
can't access my msgplus account - by BaTigolo on 02-12-2011 at 12:20 AM
RE: can't access my msgplus account - by BaTigolo on 02-24-2011 at 03:17 AM
RE: can't access my msgplus account - by Sunshine on 02-24-2011 at 09:26 AM
RE: RE: can't access my msgplus account - by BaTigolo on 02-25-2011 at 04:15 AM
RE: can't access my msgplus account - by CookieRevised on 02-24-2011 at 05:29 PM
RE: RE: can't access my msgplus account - by V@no on 02-25-2011 at 05:59 AM
RE: can't access my msgplus account - by CookieRevised on 02-25-2011 at 08:16 PM


Threaded Mode | Linear Mode
View a Printable Version
Send this Thread to a Friend
Subscribe | Add to Favorites
Rate This Thread:

Forum Jump:

Forum Rules:
You cannot post new threads
You cannot post replies
You cannot post attachments
You can edit your posts
HTML is Off
myCode is On
Smilies are On
[img] Code is On