XEROF

 

Why websites still have a password lost feature ?


As I see that hacking an account typically involves obtaining someone's account password, I'm reminded that almost all websites out there have a password lost feature which allows to send you either a new password, or equivalently the right to save a new password, usually using the same vehicle (your computer), by far the most egregious scenario, or a 2nd factor vehicle such as SMS. This feature is useful, I understand. If you lose your password, you're glad this feature is at your disposal. But should it ? Is it the best we can do to protect your account ? Or should we perhaps defer on you to make sure to never lose your password and avoid this password lost feature in the first place ? Why you ask !! because if your socially hacked, your hacker will simply use this feature to obtain a password, then own your account, and from there you don't know what happens. In a nutshell, this feature is nice, but it should not be available anymore. Don't reward account hackers! ASAP.

Posted on 12-August-2021 15:11 | Category: News | comment[0] | trackback[0]

 

 

<-- previous page

< July >
0102030405
0607080910
1112131415
1617181920
2122232425
2627282930
31



 

 

This site
Home
Articles

DevTools
CPU-Z
EditPlus
ExplorerXP
Kill.exe
OllyDbg
DependencyWalker
Process Explorer
autoruns.exe
Araxis
COM Trace injection
CodeStats
NetBrute
FileMon/Regmon
BoundsChecker
AQTime profiler
Source monitor
GDI leaks tracking
Rootkit revealer
Rootkit removal
RunAsLimitedUser(1)
RunAsLimitedUser(2)

 

 

Liens
Le Plan B
Un jour à Paris
Meneame
Rezo.net (aggr)
Reseau voltaire
Cuba solidarity project
Le grand soir
L'autre journal
Le courrier suisse
L'Orient, le jour
Agoravox (aggr)