4.9 • 696 Ratings
🗓️ 4 October 2016
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Tuesday, October 4th, 2016 edition of the Sandtonet Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Honolulu, Hawaii. |
0:12.6 | Just wrote up a quick diary with some ideas that I keep kicking around regarding password resets. Password reset is really one of those difficult questions. |
0:23.1 | A lot of sites are struggling with really finding the right trade-off |
0:28.6 | between making it not too inconvenient to the user, not too expensive to the website, |
0:35.1 | and overall just work for the user. |
0:38.3 | Now the idea that I've seen implemented a couple times, it's not my idea, but I think it's a pretty good thing. |
0:45.3 | I don't hear a lot of talk about it is what I call password buddies, essentially where you designate family members, colleagues, maybe you're a boss in sort of a corporate environment |
0:57.0 | that will have to approve your password reset. |
1:01.0 | So you're not giving them your password. |
1:03.0 | What you do is you go through the password reset as before pretty much, but then your account is locked. |
1:09.0 | And now your boss or colleague, family member, I call them password buddies, then has to |
1:16.0 | unlock your account. |
1:18.2 | I think it works pretty well because these are usually people that know you well, so they'll |
1:22.6 | have much easier time authenticating you. |
1:25.4 | Maybe you can walk over to them and do it in person than, |
1:29.6 | for example, an anonymous help desk. Big help desk and using them for password resets |
1:36.2 | almost never works well because in the end this really comes down to them asking you a couple |
1:42.0 | questions, essentially password reset questions, |
1:45.0 | and they tend to be social engineerable because they don't really know you, |
1:50.0 | so they have to essentially the exact same thing that you could do with the website itself. |
1:57.0 | Let me know what you think and if you have any suggestions on what else to do, just leave a comment please. |
2:04.6 | And in the latest version of iOS, Apple, implement a new feature where if you send a URL to a user, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.