To install click the Add extension button. That's it.

The source code for the WIKI 2 extension is being checked by specialists of the Mozilla Foundation, Google, and Apple. You could also do it yourself at any point in time.

4,5
Kelly Slayton
Congratulations on this excellent venture… what a great idea!
Alexander Grigorievskiy
I use WIKI 2 every day and almost forgot how the original Wikipedia looks like.
Live Statistics
English Articles
Improved in 24 Hours
Added in 24 Hours
What we do. Every page goes through several hundred of perfecting techniques; in live mode. Quite the same Wikipedia. Just better.
.
Leo
Newton
Brights
Milds

Password notification email

From Wikipedia, the free encyclopedia

Password notification email is a common password recovery technique used by websites. If a user forgets their password, a password recovery email is sent which contains enough information for the user to access their account again. This method of password retrieval relies on the assumption that only the legitimate owner of the account has access to the inbox for that particular email address.

The process is often initiated by the user clicking on a forgotten password link on the website where, after entering their username or email address, the password notification email would be automatically sent to the inbox of the account holder. This email may contain a temporary password or a URL that can be followed to enter a new password for that account. The new password or the URL often contain a randomly generated string of text that can only be obtained by reading that particular email.[1]

Another method used is to send all or part of the original password in the email. Sending only a few characters of the password can help the user to remember their original password without having to reveal the whole password to them.

YouTube Encyclopedic

  • 1/3
    Views:
    1 460
    3 634
    4 676
  • Account Expiry Email Notification for Active Directory Users
  • How to disable email notification when a user changes their password in WordPress
  • Get email notification when someone try to login your computer or server

Transcription

Security Concerns

The main issue is that the contents of the password notification email can be easily discovered by anyone with access to the inbox of the account owner. This could be as a result of shoulder surfing or if the inbox itself is not password protected. The contents could then be used to compromise the security of the account. The user would therefore have the responsibility of either securely deleting the email or ensuring that its contents are not revealed to anyone else. A partial solution to this problem, is to cause any links contained within the email to expire after a period of time, making the email useless if it is not used quickly after it is sent.

Any method that sends part of the original password means that the password is stored in plain text and leaves the password open to an attack from hackers.[2] This is why it is typical for newer sites to create a new password generate a token. If the site gets hacked, the password contained within could be used to access other accounts used by the user, if that user had chosen to use the same password for two or more accounts. Additionally, emails are often not secure. Unless an email had been encrypted prior to being sent, its contents could be read by anyone who eavesdrops on the email.

References

  1. ^ Maqbali, Fatma Al; Mitchell, Chris J. (2018). "Email-based Password Recovery - Risking or Rescuing Users?". Email-based Password Recovery - Risking or Rescuing Users. pp. 1–5. doi:10.1109/CCST.2018.8585576. ISBN 978-1-5386-7931-9. S2CID 53374184.
  2. ^ "Password Plaintext Storage".
This page was last edited on 26 April 2024, at 03:58
Basis of this page is in Wikipedia. Text is available under the CC BY-SA 3.0 Unported License. Non-text media are available under their specified licenses. Wikipedia® is a registered trademark of the Wikimedia Foundation, Inc. WIKI 2 is an independent company and has no affiliation with Wikimedia Foundation.