Most sites that I have used require an email address as well as asking some security questions. The most severe case of this is my Army email. I forgot my password (it is 15 characters/letters/numbers in length) and had to enter my user name, my alternate email, phone number, and then three questions where the answers were case sensitive. Only then was I able to change my password. Most sites though just ask one or two security questions as well as user name. I did a site a long time ago that asked the users first and last name, email address on record and the ID that they used to register (only asked for the last 4 of an SSN, DL, Passport, Student ID, etc..). If they did not pass that test then I offered to email them a temporary password with a link to allow them to change it permanantly once they entered their first name, last name and email address on record. (for some odd reason some could not even remember what ID type they used to register.)
Bruce On 12/20/06, Richard White <[EMAIL PROTECTED]> wrote: > > actually i have just thought of something that could happen with this > method. > > My target audience are students at university. If someone has forgot their > password and the system is designed for them to enter their email address, > it will reset their password and send them the new password - then i was > thinking that some students may get drunk and find it funny to keep entering > their friends email addresses (or people they don't like) and continue to > get them reset. > > do you guys use any way to get round this problem - maybe asking them a > security question or something like before resetting their password > > thanks > > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~| Create robust enterprise, web RIAs. Upgrade & integrate Adobe Coldfusion MX7 with Flex 2 http://ad.doubleclick.net/clk;56760587;14748456;a?http://www.adobe.com/products/coldfusion/flex2/?sdid=LVNU Archive: http://www.houseoffusion.com/groups/CF-Talk/message.cfm/messageid:264618 Subscription: http://www.houseoffusion.com/groups/CF-Talk/subscribe.cfm Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=11502.10531.4

