Prevent Misuse of the Account Recovery Function
■■
In the most security-critical applications, such as online banking,
account recovery in the event of a forgotten password is handled out-
of-band: a user must make a telephone call and answer a series of secu-
rity questions, and new credentials or a reactivation code are also sent
out-of-band (via conventional mail) to the user’s registered home
address. The majority of applications do not want or need this level of
security, and so an automated recovery function may be appropriate.
■■
A well-designed password recovery mechanism needs to prevent
accounts from being compromised by an unauthorized party, and mini-
mize any disruption to legitimate users.
Do'stlaringiz bilan baham: |