You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Right now it seems that anyone knowing the username and email of a user, as well as the hashing algorithm, would be able to reset the password. Maybe not likely, but still...
The text was updated successfully, but these errors were encountered:
A way to solve this would be to add more hashing algorithms, but... It's not really feasible. How about adding a "secret code" (like Google's Security Code) that users are presented with when they sign up?
Right now it seems that anyone knowing the username and email of a user, as well as the hashing algorithm, would be able to reset the password. Maybe not likely, but still...
The text was updated successfully, but these errors were encountered: