Re: Most secure way to reset a password via email link [message #185160 is a reply to message #185159] |
Wed, 05 March 2014 15:54 |
jvd_200089
Messages: 3 Registered: March 2014
Karma:
|
Junior Member |
|
|
On Wednesday, 5 March 2014 15:35:30 UTC, The Natural Philosopher wrote:
> Then always use https to avoid man in the middle attacks
Yes, email link will point to https:// but when using SSL what wrong with just redisplaying the password on the screen (after answer further security questions) because the data sent between server and client will by encrypted whereas an email to a standard pop3 email account won't be (or can you send SLL to a standard email)?
|
|
|