password reset
2 articles with this tag
Password reset design flaws: 5 ways accounts get taken over despite strong login, and how to fix them
A reset flow is a mechanism for letting someone who does not know the password set a new one — which makes it an authentication path in its own right. Harden the login all you like: if reset is weak, reset is your real authentication strength. Five failure shapes: guessable tokens, tokens that never expire, links that live on in a mailbox, links whose destination can be set from outside (Host header), and responses that reveal whether an account exists. The key implementation step is separating what the guidance requires from the numbers it leaves to you.
7pay Fraud (2019) — How a Payment App With No 2FA Got Taken Over
Account takeovers began the day after launch; ~808 users lost ~¥38.6M. The core failure was authentication design: (1) no two-factor authentication, so login needed only ID + password, and (2) a password reset that could send the new password to an email address other than the registered one — so fragments of personal data were enough to hijack an account. Defend by requiring 2FA on sensitive actions, restricting password reset to registered channels, detecting and locking credential-stuffing, and having auth flows reviewed by a second set of eyes before launch.