Page 1 of 1

There's got to be an easier way to get a password reset

PostPosted: Tue Oct 26, 2021 11:11 pm
by CallieO
We've known for months that Belariath is having a hard time getting initial passwords out to certain e-mail servers. Why is the only alternative, poking Ehlanna or Amethine? Is there something else we can do?

Re: There's got to be an easier way to get a password reset

PostPosted: Wed Oct 27, 2021 5:14 pm
by Ehlanna
As is so often the way, the answer isL yes, no, maybe .. ;)
The issue is that not only do we need to send the password securely from A (us, TLI, Belariath) to B (the player of the character) we also need to be sure that B is allowed to ask for a password for that character. What divides A and B is, ironcially, what also connects us - the internet! Sad to say in that yawning gulf of 'the net' are a raft load of servers hat act as way and relay stations. Thus an email (going A to B or B to A) can pass through, and be scanned by, multiple mail servers, any of which might have any preceeding mail address or relay server on a blacklist or flag the mail as spam.
Thus for reliability email does seem to be ... not that useful for such things - even if the majority do, probably, get through. What else can we do? Well, sadly, it all gets a bit meta and Catch-22 after this! You could send messages via a 'static medium' such as the message board, requesting a new passowrd (and that'd go back to getting myself or Amethine involved, though not relying upon us being seen and talked to directly). The probelm with that might be the inability to login to the message board too, especially if this is for a new player as well as character,
The other thing would be via Desdaemona in mIRC. We then need enough confirmation that B is who they say they are, which might be good enough if the command demanded the email of the character registration to be entered:
Code: Select all
/msg Desdaemona !newpassword email_address@mail.com Character Name

with Desdaemona respondign with a new, randomly generated password for thta character.

I think that should be secure enough - but I may be over=looking something, so if anyone has commenst please shout!

Re: There's got to be an easier way to get a password reset

PostPosted: Wed Oct 27, 2021 5:54 pm
by miyuka
problem I can think of is other people knowing my e-mail and then issuing this command in my stead.

Re: There's got to be an easier way to get a password reset

PostPosted: Wed Oct 27, 2021 7:49 pm
by Amethine
My opinion would be to change something else. Instead of worrying about how to retrieve or reset the password, why not allow users to create their own passwords while making a new character? That way there's no need for an email at all.

Could also provide a "recovery code" or some such that Ehl or myself can use to verify reset requests since an email is no longer essential. Don't get rid of the email requirement in making a character, this would just shift the heavy reliance of it.

The email issues don't affect everybody either, so perhaps could add a button on the site to send the recovery code to their email in case they don't make a copy of it somewhere? Would be an easy thing to display on the character edit page once logged in.

Well, thats my thinking. Apologies if there's any mistooks, typing this on my phone!

Re: There's got to be an easier way to get a password reset

PostPosted: Wed Oct 27, 2021 10:05 pm
by CallieO
Yes, I think allowing people to create their own passwords would probably make it easier. Amethine stated the obvious solution that didn't occur to me.

Re: There's got to be an easier way to get a password reset

PostPosted: Tue Nov 09, 2021 11:12 pm
by Stormbringer
Oh, no! Ehl said 'meta' and now look what's happened to FB!

Re: There's got to be an easier way to get a password reset

PostPosted: Thu Nov 11, 2021 4:39 pm
by Ehlanna
Stormbringer wrote:Oh, no! Ehl said 'meta' and now look what's happened to FB!

;)

Re: There's got to be an easier way to get a password reset

PostPosted: Sun Nov 14, 2021 9:48 pm
by CallieO
Stormbringer wrote:Oh, no! Ehl said 'meta' and now look what's happened to FB!


I *knew* she was one of the Powers That Be.