<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Devalias</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Devalias"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Devalias"/>
		<updated>2026-05-03T19:02:29Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Forgot_Password_Cheat_Sheet&amp;diff=233315</id>
		<title>Talk:Forgot Password Cheat Sheet</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Forgot_Password_Cheat_Sheet&amp;diff=233315"/>
				<updated>2017-09-15T05:43:50Z</updated>
		
		<summary type="html">&lt;p&gt;Devalias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Secret Questions ==&lt;br /&gt;
&lt;br /&gt;
Should we really be suggesting secret questions/answers in 2017? It's sort of a terrible mechanism, that largely provides little additional security benefit. There are much better options, notably 2FA.&lt;br /&gt;
&lt;br /&gt;
- Glenn 'devalias' Grant (Sept 14, 2017)&lt;br /&gt;
&lt;br /&gt;
Glenn, please see section 3. We explicitly discuss MFA as a critical step. Many companies who do a MFA workflow consider the secret questions step to be optional.&lt;br /&gt;
&lt;br /&gt;
- Jim Manico (Sept 14, 2017)&lt;br /&gt;
&lt;br /&gt;
I know it is mentioned there, but it is mentioned as a 'do this after they fail to answer the questions', only if they fail. There is nothing in that that suggests the secret questions are/could/should be optional. I was going to refer to this as a resource for how to securely implement forgot password functionality, but I don't feel it accurately represents best practice in 2017.&lt;br /&gt;
&lt;br /&gt;
- Glenn 'devalias' Grant (Sept 15, 2017)&lt;/div&gt;</summary>
		<author><name>Devalias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Forgot_Password_Cheat_Sheet&amp;diff=233314</id>
		<title>Talk:Forgot Password Cheat Sheet</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Forgot_Password_Cheat_Sheet&amp;diff=233314"/>
				<updated>2017-09-15T05:43:36Z</updated>
		
		<summary type="html">&lt;p&gt;Devalias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Secret Questions ==&lt;br /&gt;
&lt;br /&gt;
Should we really be suggesting secret questions/answers in 2017? It's sort of a terrible mechanism, that largely provides little additional security benefit. There are much better options, notably 2FA.&lt;br /&gt;
&lt;br /&gt;
- Glenn 'devalias' Grant (Sept 14, 2017)&lt;br /&gt;
&lt;br /&gt;
Glenn, please see section 3. We explicitly discuss MFA as a critical step. Many companies who do a MFA workflow consider the secret questions step to be optional.&lt;br /&gt;
&lt;br /&gt;
- Jim Manico (Sept 14, 2017)&lt;br /&gt;
&lt;br /&gt;
I know it is mentioned there, but it is mentioned as a 'do this after they fail to answer the questions', only if they fail. There is nothing in that that suggests the secret questions are/could/should be optional. I was going to refer to this as a resource for how to securely implement forgot password functionality, but I don't feel it accurately represents best practice in 2017.&lt;/div&gt;</summary>
		<author><name>Devalias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Forgot_Password_Cheat_Sheet&amp;diff=233298</id>
		<title>Talk:Forgot Password Cheat Sheet</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Forgot_Password_Cheat_Sheet&amp;diff=233298"/>
				<updated>2017-09-14T05:18:42Z</updated>
		
		<summary type="html">&lt;p&gt;Devalias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Secret Questions ==&lt;br /&gt;
&lt;br /&gt;
Should we really be suggesting secret questions/answers in 2017? It's sort of a terrible mechanism, that largely provides little additional security benefit. There are much better options, notably 2FA.&lt;br /&gt;
&lt;br /&gt;
- Glenn 'devalias' Grant (Sept 14, 2017)&lt;br /&gt;
&lt;br /&gt;
== Logging ==&lt;br /&gt;
&lt;br /&gt;
I'm surprised to see that logging isn't a consideration in password reset functionality.  Knowing that users attempted a password reset, whether the reset was successful or failed, recording details of reset sessions including IP address and other details would all seem like great suggestions.&lt;br /&gt;
&lt;br /&gt;
== More on Logging ==&lt;br /&gt;
&lt;br /&gt;
I think adding logging info like you described is a good idea. Go ahead and add it in!&lt;br /&gt;
&lt;br /&gt;
- Jim Manico Sept 2, 2015&lt;/div&gt;</summary>
		<author><name>Devalias</name></author>	</entry>

	</feed>