assurance - RE: [Assurance] credential renewal or re-issuance
Subject: Assurance
List archive
- From: "Roy, Nicholas S" <>
- To: "" <>
- Subject: RE: [Assurance] credential renewal or re-issuance
- Date: Mon, 4 Jun 2012 21:40:17 +0000
- Accept-language: en-US
A short-lived one-time use token in an email is effectively just a very high-entropy password for the person’s account only usable via a specific endpoint.
Combined with other challenges (knowledge-based authentication) then yes I think it’s effective, but the time period it’s active is also exactly the time frame when it would be desirable and possible to snoop it off the wire via SMTP in the clear. Nick From: [mailto:]
On Behalf Of Eric Goodman I think I fall into Scott's category on this as well. I'll add that just because you mail a one-time use reset token doesn't mean you can't add other security to the reset process. E.g., the one time use reset token allows you to be prompted to answer other security challenges, both of which
are required for a reset. Currently we don't use email, and instead rely on just security challenges. I'm guessing we'll to move to a hybrid approach that also relies on email, but it's fairly early on for me to be too sure . --- Eric On Mon, Jun 4, 2012 at 1:02 PM, Jones, Mark B <> wrote: I don't think that sending "A short-lived single use Secret sent to the Address of Record that the Subject must submit in order to establish a new Authentication Secret" is the same as "emailing passwords to people". I'm not saying that
the former is perfect, but it does considerably restrict who has the opportunity to control the account over the later.
|
- [Assurance] credential renewal or re-issuance, Tom Scavo, 06/04/2012
- Re: [Assurance] credential renewal or re-issuance, Cantor, Scott, 06/04/2012
- RE: [Assurance] credential renewal or re-issuance, Roy, Nicholas S, 06/04/2012
- RE: [Assurance] credential renewal or re-issuance, Jones, Mark B, 06/04/2012
- Re: [Assurance] credential renewal or re-issuance, Eric Goodman, 06/04/2012
- RE: [Assurance] credential renewal or re-issuance, Roy, Nicholas S, 06/04/2012
- Re: [Assurance] credential renewal or re-issuance, Eric Goodman, 06/04/2012
- RE: [Assurance] credential renewal or re-issuance, Jones, Mark B, 06/04/2012
- RE: [Assurance] credential renewal or re-issuance, Roy, Nicholas S, 06/04/2012
- Re: [Assurance] credential renewal or re-issuance, Cantor, Scott, 06/04/2012
Archive powered by MHonArc 2.6.16.