Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 20 Sep 2016 15:39:40 -0400
From: Scott Arciszewski <scott@...agonie.com>
To: passwords@...ts.openwall.com
Subject: Blog Post about Password Resets

Hello,

I'll not make a regular habit of doing this, but I thought this blog post
might be of interest to the readers of this mailing list:

https://paragonie.com/blog/2016/09/untangling-forget-me-knot-secure-account-recovery-made-simple

It discusses the common design flaws with password reset features and
proposes how to implement them securely. There's a TL;DR at the end.

I'd greatly appreciate any feedback or criticism anyone can offer.

Scott Arciszewski
Chief Development Officer
Paragon Initiative Enterprises <https://paragonie.com>

Content of type "text/html" skipped

Powered by blists - more mailing lists

Your e-mail address:

Powered by Openwall GNU/*/Linux - Powered by OpenVZ