Alex Rivera | Logout

What is safer? Should I send an email with a URL that expires to users to reset their password or should I email a newly generated password?

Asked 2010-02-16T23:16:18.583
24

I was wondering what would be the safer option when users have forgotten their password

  • Send a randomly generated new password to the email address (all email addresses in my database are confirmed to work).

Or

  • Send an email with a link that expires within a certain time frame where the user can reset their password.

Aside from the fact the latter uses an extra table, what do you think is safer/better practice?

Edit
Report

3 Answers

8

Send an email with a link that expires within a certain time frame where the user can reset their password.

That one, definitely.

E-mail is always in the clear (potentially your site connection may not be), and can touch more machines. Keep passwords out of e-mail. The temporary reset token also means that if the mailbox is hacked later on, the token is of no use any more.

Aside from the fact the latter uses an extra table,

It doesn't have to. You can generate a cryptographic token authorising a particular user to reset a password within a certain time frame; no extra data required.

An example using a HMAC based message authentication code (fancy hashing):

details= user_id+' '+token_expiry_timestamp
mac= hmac_sha2(server_secret, details)
token= details+' '+mac

then send the token to the user as part of the clickable URL in a mail. When you receive a click back, work out what the mac should be for that user and time with your server-side secret, and check that against the passed-in mac. If it matches, it must be a password request you signed earlier.

user_id, token_expiry_timestamp, mac= token split on ' '
details= user_id+' '+token_expiry_timestamp
if hmac_sha2(server_secret, details)!=mac
    complain
else if token_expiry_timestamp<now
    complain
else
    allow password for user_id to be changed

This requires no state, but you should use shorter expire times as the tokens could be used multiple times if you do not record usage.

answered 2010-02-16T23:19:21.383
1

Some have stated that both are equivalent - this is not true for following reasons:

1) With reset link if attacker has access to email and consequently uses reset link to change password, they will alert user even if the actual reset email and notifications are deleted by attacker. With mailing password if user requests reset and attacker sees the random password (even much later), then attacker can access user's account on your site without alerting user.

2) Also if you mail a password the user may be tempted to re-use the password on other sites and attacker with access to email has access to other sites even if the other sites were not vulnerable to account take over via account recovery.

With both random password sent in email and reset link, if attacker controls user's email, they have access to user's account. What you can do in this case, depends on how many handles on the user you have - for example, if you have their primary and alternate email address, then you should send notifications to both email accounts when reset is requested and used or if they have a phone, you could send them a text in addition to email, etc. You can monitor usage itself but that is harder.

A couple of other issues:

Can the link be used multiple times? Apart from expiring and having unpredictable value (with attached MAC so it can be verified without server state), you may want to have an internal alert go off if an attempt is made to reset password on an account multiple times (register success/failure, remote ip address, timestamp, etc) and abort after first and put the account in some inactive state.

It would be a good idea to see how much abuse is happening to see if you need more defense mechanisms to prevent account takeovers via your account recovery flows (depends on the value of an account).

Also very important in this case to keep up-to-date on email addresses and other contact information if you can (email a

answered 2010-02-17T00:03:42.847
-1

Everybody except for ceeyajoz is using flawed logic. Its hard to think about security.

Both cases use of email which is in plain text. Both are equally insecure when email gets hacked.

It doesn't matter if the URL expires since the email is hacked the hacker can just request for another password reset URL. If the temporary password has changed, the hacker could just request a new one. Either way you are screwed.

So I say just send the password, this way its one less step for the user to pick a new one.

EDIT When I said "send the password" it was in the context of the OP where you send a new random password.

answered 2010-02-16T23:53:00.937

Your Answer