Most sites that I have used require an email address as well as asking some
security questions. The most severe case of this is my Army email. I forgot
my password (it is 15 characters/letters/numbers in length) and had to enter
my user name, my alternate email, phone number, and then three questions
where the answers were case sensitive. Only then was I able to change my
password.
Most sites though just ask one or two security questions as well as user
name.
I did a site a long time ago that asked the users first and last name, email
address on record and the ID that they used to register (only asked for the
last 4 of an SSN, DL, Passport, Student ID, etc..). If they did not pass
that test then I offered to email them a temporary password with a link to
allow them to change it permanantly once they entered their first name, last
name and email address on record. (for some odd reason some could not even
remember what ID type they used to register.)

Bruce

On 12/20/06, Richard White <[EMAIL PROTECTED]> wrote:
>
> actually i have just thought of something that could happen with this
> method.
>
> My target audience are students at university. If someone has forgot their
> password and the system is designed for them to enter their email address,
> it will reset their password and send them the new password - then i was
> thinking that some students may get drunk and find it funny to keep entering
> their friends email addresses (or people they don't like) and continue to
> get them reset.
>
> do you guys use any way to get round this problem - maybe asking them a
> security question or something like before resetting their password
>
> thanks
>
> 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Create robust enterprise, web RIAs.
Upgrade & integrate Adobe Coldfusion MX7 with Flex 2
http://ad.doubleclick.net/clk;56760587;14748456;a?http://www.adobe.com/products/coldfusion/flex2/?sdid=LVNU

Archive: 
http://www.houseoffusion.com/groups/CF-Talk/message.cfm/messageid:264618
Subscription: http://www.houseoffusion.com/groups/CF-Talk/subscribe.cfm
Unsubscribe: 
http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=11502.10531.4

Reply via email to