Password reminder

Enter your WikiName and a password reminder will be sent to your registered email address.

Your WikiName:
Comments
Comment by david.bus.ucf.edu
2004-10-04 17:50:57
This is prone to abuse. I can reset anyone's password, just for fun if I wanted to. Since the email address associated with the WikiName is not public, I strongly suggest to add that field (email address associated with the WikiName) as well as the WikiName field, for the password reset to be effective.
Comment by JsnX
2004-10-04 22:11:23
Really? You can reset anyone's password? If so, I welcome you to reset my password.

Your feedback is appreciated, however you are assuming the user will remember the email address that he registered with. Is this a good assumption of someone that is already having trouble remembering one piece of information?

This action does have potential for abuse, but only by email flooding. You could keep entering in my wikiname again and again. .... Maybe this action should remember the IPs of people that have used it and only allow one or two submissions a day from that address.

Something to add to the tasklist I suppose....
Comment by DavidCollantes
2004-10-04 22:35:10
JsnX, I meant no disrespect, but if I enter JsnX on the field and hit "Send Password", what would it happen? Wouldn't your password be reset and you will get the temp one via email? Correct me if I am wrong.
Comment by DavidCollantes
2004-10-04 22:37:49
Of course, I have changed my password back.
Comment by DavidCollantes
2004-10-04 22:40:30
Another comment, entering a password such as "I really like to take baths in the morning" will not work. At least the change password option will break with such password but no feedback will be given to the user.
Comment by JsnX
2004-10-04 23:26:59
David, no disrespect was detected. And I was only slightly trying to be flippant with my answer. ....

You're still not understanding what is happening. And this is somewhat by design on my part, but maybe I should be more forthcoming. The word 'temporary' is throwing you off. You are not being sent a temporary password. You are being sent the MD5 value of your password--as it is stored in the database.

The existing password is not changed--which is stated in the email. So to answer your question, no, if you entered JsnX and hit send, my password would not be reset.

Does this info help?
Comment by DavidCollantes
2004-10-04 23:34:29
Yes, it does helps. I see how it works now. Thanks!
Valid XHTML :: Valid CSS: :: Powered by WikkaWiki