security - What's the best way to implement password recovery from a usability perspective? -
I read other password recovery questions on SO and it seems that most people have the idea of sending a password recovery link Which can only be used
Now my question is, (I know that this is subjective, but I am looking for input that you may have received from your users)
Is it comfortable for users Is it right? And by the users I mean that your grandmother is not a colleague.
As a user, I like when I can choose a new password for my choice, After that I have an activation mail, which provides clickable links for new passwords to be effective.
I do not like when a new password is sent to me, when I have to log in and edit it in my profile.
The best, though, is to have an openID login, so I do not have to keep any password.
Comments
Post a Comment