[Suggestion] Password Changing

JayC

Well-Known Member
Aug 8, 2013
5,505
1,401
Email Safety:

Instead of the email going to the new email, it goes to the old email. This way hackers like that Jordan_ kid can not change your email without access to your email (Luckily I had a different password). And in order to change your password you need email verification. This becomes a hassle if you change your password every week, but it makes it safer so people can't change your devbest password :)
 

JayC

Well-Known Member
Aug 8, 2013
5,505
1,401
In order to change your password OR email you will have to verify that it's you by logging into your email and clicking on the link

OR

Make it so users have to have a pincode but with like a million people already registered having everyone fill out a pincode is a pain.
 

RastaLulz

fight teh power
Staff member
May 3, 2010
3,934
3,933
Honestly, it's not worth the effort for a majority of users who use this site. If something does happen to someone's account, I can see any changes made to that account, and I can fix the issue from there.

But I think that the moral of the story should be that you shouldn't use the same password for anything, especially sites that are run by people who aren't trustworthy. With that being said, I'd recommend using a service like LastPass, so that using the same password or a few passwords is no longer an issue, and more importantly, this won't be an issue in the future.
 

GarettM

Posting Freak
Aug 5, 2010
833
136
There is a reason they don't verify your request every time you reset your password or email address. its a hassle and no one likes a hassle. I believe if you change your password/email you should be notified but not required to check your email to verify. There is systems that also prevent hacking.
One i am a fan of is if a irregular IP try's to login then send a code to the email address and have the user input that code to verify that the user is who they say they are.
or 3rd party authentication services like google or facebook.

Another thing to note is if some one hacks you its probably because they got a hold of your password, you gave it to them not thinking.
Hacker: Hey what is the password for you vps so i can fix this for you
You: hey my password is dadada for my vps
Hacker: Try's this password on every account you have and gets access to 9/10 of the services.
You: hey i was hacked how did this happen i never gave anyone my password!
Hacker: *hacking your dumb ass*
 

Users who are viewing this thread

Top