Security Basics mailing list archives

Re: How secure is Email based password reset?


From: "Gaurav Kumar" <gaurav () e2-labs com>
Date: Thu, 08 May 2003 18:15:30 +0530 (IST)

hi
this method is not secure thats why service like yahoo.com is not 
implementing this. the problem is that email service provider can see the 
password. also make sure that the personal question can not be framed by 
user itself like in case of indiatimes.com bcoz in many cases during user 
registration users are in such a hurry that they frame very simple question 
without giving enough importance.

Gaurav Kumar
gaurav () e2-labs com
E2 Labs,Hyderabad
India


Shekhar Jha wrote:

One of the ways to implement the password reset is to
1. Ask the personal question
2. if correctly answered, generates a unique temporary password
3. Send the password over email to user.
4. This would allow user to login once.

My query is regarding sending the password over email to user. How secure=
is
it? Given that,
1. The Server would be delivering the password email to an Internet Servi=
ce
Provider.
2. The user would typically be online waiting for the password emal to
arrive.
3. The password would be invalid after the first use.
How valid are these assumptions?

Any other pointers about different way of re-setting the password would b=
e
helpful.



---------------------------------------------------------------------------
FastTrain has your solution for a great CISSP Boot Camp. The industry's 
most 
recognized corporate security certification track, provides a comprehensive 
prospectus based upon the core principle concepts of security. This ALL 
INCLUSIVE curriculum utilizes lectures, case studies and true hands-on 
utilization 
of pertinent security tools. For a limited time you can enter for a chance 
to win one of the latest technological innovations, the SEGWAY HT. 
Log onto http://www.securityfocus.com/FastTrain-security-basics 
----------------------------------------------------------------------------






---------------------------------------------------------------------------
FastTrain has your solution for a great CISSP Boot Camp. The industry's most 
recognized corporate security certification track, provides a comprehensive 
prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case 
studies and true hands-on utilization 
of pertinent security tools. For a limited time you can enter for a chance 
to win one of the latest technological innovations, the SEGWAY HT. 
Log onto http://www.securityfocus.com/FastTrain-security-basics 
----------------------------------------------------------------------------


Current thread: