Using only e-mail address to "I forgot my password"

https://www.phpbb.com/ideas/
Post Reply
User avatar
robra
Registered User
Posts: 147
Joined: Thu Dec 09, 2010 2:09 am
Location: Brazil

Using only e-mail address to "I forgot my password"

Post by robra » Sun Jul 14, 2013 8:43 pm

How the user will get the new password if only remember your e-mail address and not your username :?:
So, will be better to user to inform only the your e-mail account to receive your new password.

Thanks.

----------

View idea at: Using only e-mail address to "I forgot my password"

Posted by robra

brunoais
QA Team
Posts: 418
Joined: Wed Jun 18, 2008 10:50 am

Re: Using only e-mail address to "I forgot my password"

Post by brunoais » Mon Jul 15, 2013 4:03 pm

The current system allows two different users to have the same e-mail address. That's why it is like that currently.
Anyway, there's already an RFC at area51 about this and one of the ideas there is to make it this way and then send the possibility for all usernames that has that e-mail.

User avatar
nickvergessen
Former Team Member
Posts: 4397
Joined: Mon Apr 30, 2007 5:33 pm
Location: Stuttgart, Germany
Name: Joas Schilling
Contact:

Re: Using only e-mail address to "I forgot my password"

Post by nickvergessen » Mon Jul 15, 2013 4:15 pm

brunoais can you link to the RFC?
No Support via PM


User avatar
keith10456
Registered User
Posts: 2315
Joined: Thu Feb 24, 2005 6:55 pm
Contact:

Re: Using only e-mail address to "I forgot my password"

Post by keith10456 » Tue Jul 16, 2013 6:08 pm

This makes it easier get into someone's account.

Hardolaf
Google Summer of Code Student
Posts: 10
Joined: Sat Mar 31, 2012 11:01 pm
Name: Joseph Warner

Re: Using only e-mail address to "I forgot my password"

Post by Hardolaf » Tue Jul 16, 2013 6:36 pm

Limiting this feature to unique e-mail addresses might be a better method.

brunoais
QA Team
Posts: 418
Joined: Wed Jun 18, 2008 10:50 am

Re: Using only e-mail address to "I forgot my password"

Post by brunoais » Tue Jul 16, 2013 8:57 pm

Hardolaf wrote:Limiting this feature to unique e-mail addresses might be a better method.
How would you do with installations with multiple users with the same e-mail?

User avatar
nickvergessen
Former Team Member
Posts: 4397
Joined: Mon Apr 30, 2007 5:33 pm
Location: Stuttgart, Germany
Name: Joas Schilling
Contact:

Re: Using only e-mail address to "I forgot my password"

Post by nickvergessen » Wed Jul 17, 2013 7:16 am

keith10456 wrote:This makes it easier get into someone's account.
You would still need access to the email account of your victim, right?
No Support via PM

User avatar
callumacrae
Former Team Member
Posts: 2662
Joined: Tue Feb 12, 2008 12:28 pm
Location: London, UK
Name: Callum Macrae
Contact:

Re: Using only e-mail address to "I forgot my password"

Post by callumacrae » Wed Jul 17, 2013 3:58 pm

nickvergessen wrote:
keith10456 wrote:This makes it easier get into someone's account.
You would still need access to the email account of your victim, right?
Yep, and if you've got that you've probably got their email address anyway.
macr.ae = my website. you probably won't like it.
Proud user ofProud user of

Hardolaf
Google Summer of Code Student
Posts: 10
Joined: Sat Mar 31, 2012 11:01 pm
Name: Joseph Warner

Re: Using only e-mail address to "I forgot my password"

Post by Hardolaf » Thu Jul 18, 2013 3:15 am

brunoais wrote:
Hardolaf wrote:Limiting this feature to unique e-mail addresses might be a better method.
How would you do with installations with multiple users with the same e-mail?
As I said, unique e-mail addresses. So if the same e-mail address is used for two or more accounts it would not work.

Post Reply

Return to “phpBB Ideas”