Closed (works as designed)
Project:
Password reset
Version:
5.x-1.1-beta
Component:
User interface
Priority:
Normal
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
9 May 2008 at 21:12 UTC
Updated:
28 Feb 2009 at 07:07 UTC
Great work so far!
Perhaps allow the end user to select three out of all available questions. This will increase security while also increasing flexibility -- for example, some of my users don't have library cards, while others have never driven a car -- but out of many possible questions each can find about three that works for them.
Comments
Comment #1
Zen commentedAllow multiple questions and answers for each user so he can try and get at least one of them right? Please explain - thanks :)
Comment #2
neopoet commentedSay you have only one question: "What is your library card number?"
Some users don't have library cards!
Imagine instead you allowed a person, on their account editing page, to select what question they would like to have as a reset question. There would be enough questions so that each person would be able to find a question that is both relevant and secure.
Of course, once they select one question out of a list of several, that question would be the one that they have to answer when they reset their password.
Perhaps an example would be helpful.
Joe Smith registers on Example.com. He has to choose between three possible reset questions-- "What is your library card number?", "What is the first car you ever owned?" and "What is your father's name?" Since he is an orphan and never owned a car, he selects the first question, and enters his card number, "129020421". A few days later he forgets his password, and goes to reset it. He pulls out his library card, types in the right answer-- 129020421-- and the site allows him to choose a new password.
This example is a little simplified, because for real security you might want to ask a TOTAL of three questions, and you might give several choices for each question (so their might be a bank of say, 12 different possible questions and users must select three).
Comment #3
Zen commentedWell, that's how the module currently works. You can add questions from the admin interface.
-K