Changes

Reset passwords and security questions

70 bytes added, 8 years ago
changed tool to bypass url conflict
|Scenario Task Format=Solution
|Scenario Task Parent=I want to protect my email account from unauthorised access
|Scenario Task Type=Hacking, Unauthorised Access|Scenario Tools and Services=KeePass Password Safe|Scenario Task Description=Password are easily forgotten (unless you are using a [https://securityinabox.org/en/guide/keepass/windows password program]). This is why most service providers offer several opportunities for you to reset your password by sending you an email or by asking you a personal question of your choice to prove your identity. Whilst often necessary, both options may result in a security risk and need to be thought through carefully in advance. For an excellent description of the problem, you can read this [http://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/ Wired article by Matt Honan].To make a long story short:
# Resetting a password by sending the code to another email account opens up another attack vector for the hacker. If they can break into one account and then request the reset password to another account to be sent there, you are worse off than before.