LWN.net Logo

password recovery

password recovery

Posted Feb 8, 2010 9:21 UTC (Mon) by robbe (guest, #16131)
Parent article: Encrypting users' web data with Grendel

How about on account creation the answers to a few security question are
queried from the user. These are used to encrypt recovery information,
and the resulting bundle is *not* stored at the website, but presented as
a file to download and store for the user.

This means that if the user wants to recover a forgotten password he or
she needs to proof knowledge (not-that-secure security questions) *and*
ownership (of the file).

If the webpage could check for the continued presence of this "backup
file", that would be nice -- but I fear giving scripting this privilege
is a security problem.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds