Alex Rivera | Logout

PHP password recovery

Asked 2011-01-21T20:56:03.743
12

I realize that for security that passwords should not be stored in a DB as plaintext. If I hash them, I can validate them for login purposes.

But if I want to set up a password recovery system, what's the best strategy since there is no undoing of the hashing?

Could someone give me a brief overview of a good and secure strategy for storing and recovering passwords?

Edit
Report

1 Answer

39

You can not recover password that were hashed, neither should you.

What you should do instead is:

  1. Put some verification on the password reset request, like CAPTCHA.
  2. Create an one-time random code and send a link with it to user's email.
  3. Have this code expire in, say, an hour.
  4. Have this code expire immediately once used.
  5. On the link with the code, if it validates, allow him to change his password.
  6. Notify him that the password was changed, but do not send it in the email.
answered 2011-01-21T21:00:31.893

Your Answer