| Author |
Post |
|
|
#1 Tue Mar 27, 2007 9:04 pm
|
|
Member
Registered: Mar 2007
Posts: 1
|
When requesting password we need to enter the username and email adress. I think the script generates a random pw and mails it to the address. But if a user enters this information from another user he can easily change his password. How can we prevent this and make passwod request difficult or can we cancel this option? Thank you.
|
|
|
#2 Wed Mar 28, 2007 1:16 pm
|
|
Developer
Registered: Apr 2004
Posts: 2180
Location: Belgium
|
This behavior cannot be changed in UseBB 1. UseBB 2 could send a confirmation link first, eventually allowing the user to set the password. Moved to feature requests.
|
|
|
#3 Sat Aug 25, 2007 9:40 am
|
|
Member
Registered: Oct 2006
Posts: 37
|
I don't think that this is major issue. As I know not so many people share their email addresses with other people, when we are talking about forums. _______________ "Three things cannot be long hidden: the sun, the moon, and the truth." - said by Buddha.
|
|
|
#4 Sat Aug 25, 2007 10:02 am
|
|
Developer
Registered: Apr 2004
Posts: 2180
Location: Belgium
|
The issue is that you can get anyone's password altered if you know the username and e-mail address.
|
|
|
#5 Sat Aug 25, 2007 11:58 pm
|
|
Member
Registered: Apr 2006
Posts: 54
Location: Athens, Greece
|
Do you have to know both the username and the e-mail address in order to change a user's password? Sorry, I don't have a UseBB installation right now to find the answer to this. 
|
|
|
#6 Sun Aug 26, 2007 8:31 am
|
|
Developer
Registered: Apr 2004
Posts: 2180
Location: Belgium
|
|
|
|
#7 Mon Aug 27, 2007 3:52 pm
|
|
Member
Registered: Mar 2006
Posts: 7
Location: Rotterdam, The Netherlands
|
even then- if you ask me.. it's still not that bad. so what if the pass changes? the new password will be sent to the _mail_ anyway. it becomes troublesome if the pwchange can read the mail- but then again.. a lot of people use the same password for everything. so I wouldn't worry to much about it  _______________ If I where the rain, that binds the Heaven and Earth together who in all eternity will never mingle, will I be able to bind two souls together?
|
|
|
#8 Mon Aug 27, 2007 5:35 pm
|
|
Developer
Registered: Apr 2004
Posts: 2180
Location: Belgium
|
You can't get hold of the password, but it may be troublesome when one keeps on resetting other people's password. Also, sending a password via e-mail isn't considered secure. That's why in 2.0 you will receive a link via email where you will be able to set a new one.
|