On Jul 26, 2009, at 3:35 PM, Yarko Tymciurak wrote: > On Sun, Jul 26, 2009 at 5:23 PM, Sebastian E. Ovide <sebastianov...@gmail.com > > wrote: > personally I prefer the method adopted by most of the websites... > they send you a link valid for x minutes that you can use to reset > your password. > > I find very annoying that anybody can reset my password ! > > Good point.... another option would be to do what banks / credit > card companies do: save some set of challenge questions before > allowing password reset.
By coincidence, I had two password-reset attempts on my gmail account last week. Here's the message they send; notice that they explicitly mention the possibility that the request came from some third party. I don't recall exactly what the rest of their process is, but presumably one enters a new password (as opposed to being assigned one). (BTW, what happens in the present scheme if the new random password fails to validate? It could be a little confusing. > To initiate the password reset process for your > jlun...@gmail.com Google Account, click the link below: > > http://www.google.com/accounts/RP?c=CPHxxO.....LDEjKP03tMB&hl=en > > If clicking the link above doesn't work, please copy and paste the > URL in a > new browser window instead. > > If you've received this mail in error, it's likely that another user > entered > your email address by mistake while trying to reset a password. If > you didn't > initiate the request, you don't need to take any further action and > can safely > disregard this email. > > Thank you for using Google. > > For questions or concerns about your account, please visit the > Google Accounts > Help Center at http://www.google.com/support/accounts/ > > > This is a post-only mailing. Replies to this message are not > monitored > or answered. --~--~---------~--~----~------------~-------~--~----~ You received this message because you are subscribed to the Google Groups "web2py-users" group. To post to this group, send email to web2py@googlegroups.com To unsubscribe from this group, send email to web2py+unsubscr...@googlegroups.com For more options, visit this group at http://groups.google.com/group/web2py?hl=en -~----------~----~----~----~------~----~------~--~---