ArcGIS Online: Strengthen the Reset Password Procedure

346
1
05-19-2014 05:33 AM
Status: Open
LiamMurray1
New Contributor III
The process by which a user can reset their account password seems open to potential abuse. As it stands, a user resets their password as follows:
  1. Click "Forgot my password" on the login page
  2. Enter username and click continue
  3. The user is prompted to enter the answer to their security question.
  4. If correctly answered, the user is then asked to reset their password from this same scree
  5. If incorrectly answered, the user can continue trying until they enter the correct one. There does not appear to be any limit on incorrect attempts.
This causes concern because users' security questions are not generally as complex as their password. In this current process, any potential wrong-doer need only know the structure used for an organisation's usernames and to take a lucky guess at their security question to gain full access to their account.

What we would like to see, is a process similar to the following:
  1. Click "Forgot my password" on the login page
  2. Enter username and click continue
  3. The user is prompted to enter the answer to their security question.
  4. If correctly answered, a password reset link is emailed to the user's registered email address
  5. If incorrectly answered three times in a row, the account is locked out and an email is sent to the user's registered email address.

Tags (1)
1 Comment
RandallWilliams

In the current ArcGIS.com release, password reset emails are sent to members who request to update a password. The email contains a link to a password reset page. The link is valid for 60 minutes starting from when a password reset was requested. 

Once the link is received by a user and opened, at that point a user is prompted to answer the password reset question.