Kaishin, inc.

  • Random
  • Archive
  • RSS
  • Ask me anything
If you have a “forgot password” feature that sends password reset links via email, then you should be putting auto-login tokens in every single link URL you send to your users via email.
Jeffrey Paul makes a good point. Security shouldn’t be a concern if you are already sending tokens for password resets. Also, if my email is hacked into, I would have much more to worry about than Facebook and Twitter passwords.

Source: sneak.datavibe.net

    • #web
    • #ux
    • #security
  • 8 months ago
  • Permalink
  • Share
    Tweet
← Previous • Next →

About

Avatar A personal blog of a designer, gamer and Japan geek

Me, Elsewhere

  • kaishin on Dribbble
  • kaishin on Forrst
  • @kaishin on Twitter
  • kaishinlab on Flickr
  • kaishin on Pinboard
  • kaishin on Foursquare
  • My Skype Info
  • kaishin on github

Twitter

loading tweets…

  • RSS
  • Random
  • Archive
  • Ask me anything
  • Mobile

© 2011 KaishinLab. Effector Theme by Carlo Franco.

Powered by Tumblr