shiva
I agree the passwords are reset only after email verification, I have not written anything about that in post - what I was pointing is that the password is reset to "password" for everyone who does that and not auto generated - I am glad it is in the radar and actions are taken.
Story: Sphinn - Forgotten Password?
@Michelle:
Hi, Again, I have not misintrepreted how an activation email is sent and I didn't question that at all and didn't go to that topic anywhere. Being a technical person myself - I would not approve a logic that gives a standard password for anyone who resets their password.
Assume we have a banking application and if and when a user (and that too any user) resets their password, if the application changes the password to be password - will we agree?
Jeremy, thanks for desphunn, please take look at the complete article before judging based on a title.
« previous1 next »


Story: Sphinn - Forgotten Password?