Sorry this site requires JavaScript to be enabled in your browser. See the following guide on How to enable JavaScript in Internet Explorer, Netscape, Firefox and Safari. Alternatively you may be blocking JavaScript with an advert-related or developer plugin. Please check your browser plugins.

Logic behind forgot password on Sphinn.com website could hurt the site in long run! These are steps to be taken OnSite and explains how important is a small technical part of a website. Not too late now for Sphinn.com, just take some couple of hours in development team and fix the logic. And if you have some sort of same logic in your website, take action right now. Read more for details..
Comments8 Comments  

Comments

Avatar
from Feydakin 1257 Days ago #
Votes: 2

I have to ask, did you contact them about this before you made your blog post??

Avatar
from evilgreenmonkey 1256 Days ago #
Votes: 0

This post is very misleading. Passwords are only reset after email verification - if you don’t click the link in the email, your password isn’t reset. We also tell people to change the password as soon as they login with the default password. This was already on our radar, and we will be changing the process of resetting a password. It is not however a security risk.

Avatar
from shiva 1256 Days ago #
Votes: 0

I agree the passwords are reset only after email verification, I have not written anything about that in post - what I was pointing is that the password is reset to "password" for everyone who does that and not auto generated - I am glad it is in the radar and actions are taken.  

Avatar
from shiva 1256 Days ago #
Votes: 0

@Michelle:Hi, Again, I have not misintrepreted how an activation email is sent and I didn’t question that at all and didn’t go to that topic anywhere. Being a technical person myself - I would not approve a logic that gives a standard password for anyone who resets their password. Assume we have a banking application and if and when a user (and that too any user) resets their password, if the application changes the password to be password - will we agree?

Avatar
from mychildbook 1002 Days ago #
Votes: 0

Hm, maybe it is not such a big problem that password is changed to default "password" phrase, but for me wasthe  problem where to change the password. They said only to change password when log again, but they don’t say where to click to change it... I’m not new to internet and computers, but despite that, it took me more than 15 minutes to find the way. Try to imagine how much time it would take for an unexperienced person to find it? Or a person who is not so good in english? And try to imagine that during that time someone can succeed to hack somebody’s account.

Avatar
from evilgreenmonkey 935 Days ago #
Votes: 0

Misleading information that portrays a security risk.

Avatar Administrator
from Michelle 935 Days ago #
Votes: 0

What evilgreenmonkey said. Misleading post that leaves out a crucial detail about how something actually functions.

Avatar Moderator
from Jill 935 Days ago #
Votes: 0

If people who reset their password don’t know enough to change it once they login again, especially when it’s something like ’password’ then it’s their own fault if hacked.

Upcoming Conferences

Search Marketing ExpoSearch Engine Land produces SMX, the Search Marketing Expo conference series. SMX events deliver the most comprehensive educational and networking experiences - whether you're just starting in search marketing or you're a seasoned expert.



Join us at an upcoming SMX event:

Upcoming Webcasts

Search Marketing Now Learn more about search marketing with our free online webcasts and webinars from our sister site, Search Marketing Now. Upcoming online events include: