Post
Topic
Board Meta
Re: Secret Question issue: theymos, consider hassle to recover locked account
by
mdayonliner
on 27/04/2018, 12:25:10 UTC
-snip-
The secret question is usually the last thing that people will resort to when they have lost their password. With an email, you can retrieve the password through a simple reset. When a user doesn't have an email/loses their email wouldn't it make sense to lock an account for verification if they reset using the secret question?

Especially considering the fact that the answer is usually far less secure than passwords.

Of course not. I do not know how the SMF reset function work but the stander reset procedures should be....
...When the Secret answer match with the users input then send a reset link or a new pass to the registered email. 

However I understand the issue here. Since we do not need to verify an email at the time of registration so it's complected.


~~
Bill I said IMO. Please please don't through out argues out of no where. Please do not blame me saying...
Quote
....doesn't read stickies or educate themselves on the security of their accounts?
Please.
This forum is full with information and but not organised for sure. There are a lot of information I have not even encountered yet so do you.

Quote
I'm a little uninformed on this issue, in the sense that I don't know if the Secret Question works at all.
See your statement. Does that not mean that you are also in doubt.

You can not expect someone to know everything about everything. This forum is an ocean mate.


You see the fears bill?
If anyone has disabled this function successfully, please let me know, I'm not willing to try myself.

I was considering disabling the secret question option if and when my regular account is unlocked, but afraid to touch it as well.

Please bill please... Thank you for understanding.