On Fri, 20 May 2005 20:41:51 GMT, Mark McIntyre
<(E-Mail Removed)> wrote:
>On Fri, 20 May 2005 08:03:09 +0100, Andrew Norman <(E-Mail Removed)>
>wrote:
>
>>On Fri, 20 May 2005 08:00:37 +0100, Andrew Norman <(E-Mail Removed)>
>>wrote:
>>
>>I should have said "password reset" rather than recovery.
>
>probably because far too many people choose idiotic security questions
>(encouraged by idiotic banking practices which suggest things like
>spouses birthday, mothers maiden name, etc), and with a web-based
>form, a thief could have several tries if they got it wrong the first
>time.
True, but it is perfectly possible to rate limit the web based form so
that you don't get many useful tries at it.
Also, for most accounts Plusnet have a credit card or bank
account/sort code. So they could easily do the "provide the 2nd, 3rd
and 9th digit" approach that banks use on passwords.
--
Andy Norman
(E-Mail Removed)
http://www.norman.cx/
Replace the fish with my first name to reply