Security Basics mailing list archives

Re: How secure is Email based password reset?


From: Chris Burton <cyberhiker99 () yahoo com>
Date: Thu, 8 May 2003 08:29:59 -0700 (PDT)

The way that we work it here is that we create an
encrypted package to send over the e-mail.  I think we
use PGP.  The person on the other end know the
passphrase because it was given to them at some point
in the past.  


--- Shekhar Jha <shekhar-jha () usa net> wrote:
One of the ways to implement the password reset is
to
1. Ask the personal question
2. if correctly answered, generates a unique
temporary password
3. Send the password over email to user.
4. This would allow user to login once.

My query is regarding sending the password over
email to user. How secure is
it? Given that,
1. The Server would be delivering the password email
to an Internet Service
Provider.
2. The user would typically be online waiting for
the password emal to
arrive.
3. The password would be invalid after the first
use.
How valid are these assumptions?

Any other pointers about different way of re-setting
the password would be
helpful.




---------------------------------------------------------------------------
FastTrain has your solution for a great CISSP Boot
Camp. The industry's most
recognized corporate security certification track,
provides a comprehensive
prospectus based upon the core principle concepts of
security. This ALL INCLUSIVE curriculum utilizes
lectures, case studies and true hands-on utilization
of pertinent security tools. For a limited time you
can enter for a chance
to win one of the latest technological innovations,
the SEGWAY HT.
Log onto

http://www.securityfocus.com/FastTrain-security-basics

----------------------------------------------------------------------------



__________________________________
Do you Yahoo!?
The New Yahoo! Search - Faster. Easier. Bingo.
http://search.yahoo.com

---------------------------------------------------------------------------
FastTrain has your solution for a great CISSP Boot Camp. The industry's most 
recognized corporate security certification track, provides a comprehensive 
prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case 
studies and true hands-on utilization 
of pertinent security tools. For a limited time you can enter for a chance 
to win one of the latest technological innovations, the SEGWAY HT. 
Log onto http://www.securityfocus.com/FastTrain-security-basics 
----------------------------------------------------------------------------


Current thread: