Alex Rivera | Logout

Effective Techniques for Password Retrieval in Modern Web Applications

Asked 2009-05-26T14:02:36.497
18

We've been working on web application where in we need to implement traditional web-apps functionality of password retrieval. According to the trends there are approaches like..

  1. Sending Password reset link to user's email.
  2. Asking Secret Question to the user for Password recovery.
  3. Resetting the existing Password and creating a new password and sending it to the user. This may also force the user to change the password upon next logon.

Do we have any non-traditional technique for implementing password retrieval mechanism ? What other approaches you've tried for this ?

Thanks.

Edit
Report

1 Answer

8

Other options I saw in practice would include:

  • allowing a second password when something goes wrong - something like the Super-PIN used with cell phones.
  • creating a file token(usually a PGP key) that the user will download at account creation and store it on a USB Stick, or archive it for later use. When there's a problem the user will upload the token, thus proving that he is the "owner" of the account, and the application than will let the user to change the password. This can be a constant token, or a file with several tokens (similar to an online banking TANs) - each time a token is used, it's also invalidated.

The above methods are not that simple to implement, but are quite user friendly (since there's nothing new about them and are present other in day by day situations).

answered 2010-07-18T22:19:52.987

Your Answer