The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
![]()
I have two VB installs, running 3.0 and 3.6.
My users are not always the most tech-savvy, and so they get really confused by the lost password system. The way the standard lost pw system works is that it emails the user a link to generate a new numeric (ex: 3450596) password, and then requires the user to use the user cp to change the password to something the user wants. What would be more user-friendly, in my opinion, would be to bypass the numeric password, and send an email that says click here to update your password. The change password url would have some sort of quick-expiring querystring hash to prevent unauthorized access. I think this would be as secure as the existing system, since both will allow the email recipient to change the password. Mine just has fewer steps for the user to take. I have been searching here for a mod like this, and didn't see any, but "lost password" is not a very unique search string, so maybe it is there and I just can't find it. Does anyone know of a mod that does this? Does anyone think this would be useful? Does anyone think this is less secure than the existing system? Thanks for a great site. I hope I put this in the right forum. I come here whenever I need something, and it always works out. Jon |
#2
|
||||
|
||||
![]()
I have asked for the same thing. It seems the password is saved as a one-way encrypted hash, which is ridiculous for user management and convenience. My users have allo sorts of problems trying to work out how to work with the resent temp one and then updating it etc etc. I to am hoping someone makes a mod for this to fix the moist annoying issue and it is perhaps the worst thing about what it otherwise a really good forum solution.
Many of my users have however left the site due to this continual problem! |
#3
|
||||
|
||||
![]()
I usually find that more people message asking for password resets than those who actually attempt to use the form. I think it is something that could be improved upon for future builds. How to best do it securely, that's up for debate.
|
#4
|
||||
|
||||
![]()
I would think the obvious reason it works this way is to stop other users locking you out of your own account. If you can goto a link that just resets your password then so can I, therefore resetting your password and locking you out. Better still I could write a small script that does it for every user - basic denial of service attack.
|
#5
|
|||
|
|||
![]()
Think that's a no then
![]() |
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|