Speak Friend, And Enter December 13, 2010 3:32 PM   Subscribe

It would be nice if the system would generate an automatic email confirming password resets.

Having spent much of my day resetting every goddamn password I've ever used anywhere ever (thanks, Gawker! GDIAF!), I finally got around to resetting the password that I've used on MeFi since, um, I signed up.

Many of the sites I visited today sent me confirmation emails that my password had been reset. I like receiving these emails, as I am one to clutch tenaciously at the illusion of internet security.

Is a password-reset confirmation auto-email a Thing Y'all Could Do? That'd be nifty.

Relentlessly clogging your workday with trivial requests,

I remain,

Not Todd Lokken
posted by BitterOldPunk to Feature Requests at 3:32 PM (28 comments total)

Sure, just give me your password, I'll send you one.
posted by nomadicink at 3:35 PM on December 13, 2010 [4 favorites]


It's CHOKEONABAGOFDICKS
posted by BitterOldPunk at 3:39 PM on December 13, 2010 [6 favorites]


Mefi doesn't send confirmation emails. Cortex just rides his bike over and sings you a little jingle. Do you live far from Portland?
posted by special-k at 3:39 PM on December 13, 2010 [2 favorites]


case sensitive?
posted by nomadicink at 3:39 PM on December 13, 2010 [2 favorites]


Many of the sites I visited today sent me confirmation emails that my password had been reset.

Did those sites also require your old password like we do? You get a confirmation of the change at the site after we verify your ID. I'm not sure how the auto-email enhances security.
posted by pb (staff) at 3:42 PM on December 13, 2010


The point of a password-reset email is not so much that I get told when I've reset my password (I know that, because I just did it) as that I get told when a black hat resets it for me. If I have a weak password, it would be nice for the account to issue one last gasp before being fully hijacked.

Notification of an email address change, sent to the old email address, would be a good thing for the same reason.

On the other hand, I'm unlikely to suffer much damage even in the unlikely event that some vicious desperado successfully impersonates me for a while on Mefi.
posted by flabdablet at 3:55 PM on December 13, 2010 [1 favorite]




OrderCializViagra Online & Save 75-90%

0nline Pharmacy NoPrescription required
Buy Canadian Drugs at Wholesale Prices and Save 75-90%
FDA-Approved drugs + Superb Quality Drugs only!
Accept all major credit cards
        Order Today! From $1.38
posted by flabdablet at 3:56 PM on December 13, 2010 [3 favorites]


Yeah, the auto-confirm is not so much to enhance security but to a) give me a time-stamped record of when I changed it and to b) alert me if anyone else tries to hijack my account.
posted by BitterOldPunk at 3:58 PM on December 13, 2010 [1 favorite]


Mefi doesn't send confirmation emails. Cortex just rides his bike over and sings you a little jingle.

WANT
posted by rtha at 4:00 PM on December 13, 2010


ah ok, I see. Yeah, that makes sense even though it feel like overkill for MetaFilter. Since it's not standard practice for sites like MeFi I'm afraid it could lead to some confusion and OMG I DID WHAT moments when the email comes in. But maybe we could warn people up-front when they change their password.

We also have a whole slew of people without verified email addresses. They'd be out of luck on this.
posted by pb (staff) at 4:02 PM on December 13, 2010


I can see how it might be shading into overkill, since there's really no sensitive information attached to one's account. I guess I'm now a bit gun-shy since having found so many of my online accounts compromised because years ago I once just HAD to tell someone on Kotaku how wrong they were about Final Fantasy IX.

No biggie.
posted by BitterOldPunk at 4:10 PM on December 13, 2010


Shit, I hope Cortex brings his giant balloon snowtires with him, or his ride is going to bog down pretty quick on the way to my snowed-in house. But I'm going to get all ready with craft beer and donuts and a fresh pillow and blankie in case he needs to stay over on the couch.

(This time I'm quitting you for sure, Jezebel).
posted by padraigin at 4:24 PM on December 13, 2010


Can we not implement secure password changes via carrier pigeon? I mean, COME ON, it's the 21st Century already!
posted by blue_beetle at 4:41 PM on December 13, 2010


We were gonna switch over to a distrans architecture, but recent CHOAM price-hikes and the attendant rise in cost of the spiceplastic components for the imprinting machines has made that fiscally untenable for the time being.
posted by cortex (staff) at 4:58 PM on December 13, 2010 [2 favorites]


hunter2
posted by Duke999R at 5:06 PM on December 13, 2010 [2 favorites]


Earlier today on twitter, cortex wrote: Just did some math. I've written upwards of 1.7 million words on metafilter over the years.

That last comment should NOT count toward the total.
posted by oneswellfoop at 5:08 PM on December 13, 2010


special-k: "Mefi doesn't send confirmation emails. Cortex just rides his bike over and sings you a little jingle. Do you live far from Portland"



Cortex how would you like to make $20 for your favorite charity?
posted by boo_radley at 5:21 PM on December 13, 2010


Cortex already donated in town.
posted by mmmbacon at 5:56 PM on December 13, 2010


Metafilter: Cortex already donated in town.
posted by nomadicink at 6:14 PM on December 13, 2010


Hey BOP, are you aware of KeePassX? It will improve your life, if not.
posted by flabdablet at 6:36 PM on December 13, 2010


And while I'm thinking about password reset confirmation mails: I'm seriously thinking of changing to a different electricity retailer, simply because their web stuff is so, so lame. They have no user password reset facility at all; closest thing apparently, and what they advise me to use, is a "forgot my password" link that only functions when I'm logged out and causes the site to send me an email including my account ID and password in plain text.

Their help desk script monkeys are cheeky enough to assure me that this is "secure".

Mefi is streets ahead of those dickheads.
posted by flabdablet at 8:47 PM on December 13, 2010


You'll get nothing at all and you'll like it!
posted by nola at 9:24 PM on December 13, 2010


I used to have nothing at all and I loved it.
posted by Sailormom at 9:30 PM on December 13, 2010




You all just use the password 'password,' amiright?
posted by bluedaisy at 10:08 PM on December 13, 2010


Email confirmation would be good. If only because I always get excited when I get a MeMail showing up in my in-box.
posted by arcticseal at 10:19 PM on December 13, 2010


I named my cat 2g+7mR;G0j/u.
posted by Zozo at 8:31 AM on December 14, 2010


I named my cat 2g+7mR;G0j/u.

Oh, after the noise it makes when it's puking in your slippers, yeah?
posted by nebulawindphone at 8:36 AM on December 14, 2010


« Older Groupons for charity   |   LinkedIn profile linking Newer »

You are not logged in, either login or create an account to post comments