ArcGIS Online: Strengthen the Reset Password Procedure

Idea created by LiamMurray on May 19, 2014
    New
    Score80
    • benoconnor
    • dbrown204
    • joanna.jaworska
    • AnthonyHunt
    • gg3cpg
    • basileChandesris
    • rfairhur24
    • LiamMurray
    The process by which a user can reset their account password seems open to potential abuse. As it stands, a user resets their password as follows:
    1.           Click "Forgot my password" on the login page
    2.           Enter username and click continue
    3.           The user is prompted to enter the answer to their security question.
    4.           If correctly answered, the user is then asked to reset their password from this same scree
    5.           If incorrectly answered, the user can continue trying until they enter the correct one. There does not appear to be any limit on incorrect attempts.
    This causes concern because users' security questions are not generally as complex as their password. In this current process, any potential wrong-doer need only know the structure used for an organisation's usernames and to take a lucky guess at their security question to gain full access to their account.

    What we would like to see, is a process similar to the following:
    1.           Click "Forgot my password" on the login page
    2.           Enter username and click continue
    3.           The user is prompted to enter the answer to their security question.
    4.           If correctly answered, a password reset link is emailed to the user's registered email address
    5.           If incorrectly answered three times in a row, the account is locked out and an email is sent to the user's registered email address.