Results 1 to 3 of 3
  1. #1
    Join Date
    Mar 2010
    Location
    Finland
    Posts
    463
    Plugin Contributions
    0

    Default "Forgot password" proclaims success every time

    Is this intended functionality?

    The customer is currently not made aware of their, e.g. possible mistake in the address - they are just left hanging.
    Last edited by kalastaja; 25 Apr 2017 at 04:20 PM.

  2. #2
    Join Date
    Jan 2004
    Location
    N of San Antonio TX
    Posts
    9,151
    Plugin Contributions
    11

    Default Re: "Forgot password" proclaims success every time

    The idea is to make the hacker think they are going to be getting a new password.
    Of course, with open source, you can always search for the wording and change it to "If the address you used is registered with us, a new password is on it's way."
    Personally, I'd just leave it alone.

  3. #3
    Join Date
    Nov 2005
    Location
    los angeles
    Posts
    2,691
    Plugin Contributions
    9

    Default Re: "Forgot password" proclaims success every time

    Quote Originally Posted by dbltoe View Post
    The idea is to make the hacker think they are going to be getting a new password.
    Of course, with open source, you can always search for the wording and change it to "If the address you used is registered with us, a new password is on it's way."
    Personally, I'd just leave it alone.
    my opinion is that it is very frustrating for the customer, and that hackers are far more sophisticated than some people give them credit.

    i see far more brute force attempts at logging into a server, than someone trying to hack a user account.

    this topic was addressed here:

    https://github.com/zencart/zencart/issues/1295

    and for v160, there will be a switch which allows the store owner to say whether the email address is registered or not.

    best.
    author of square Webpay.
    mxWorks has premium plugins. donations: venmo or paypal accepted.
    premium consistent excellent support. available for hire.

 

 

Similar Threads

  1. v151 getting no emails for " Forgot password"
    By awk_grep in forum Managing Customers and Orders
    Replies: 0
    Last Post: 31 Dec 2013, 05:06 AM
  2. v139h PP Express - 3 log files show "Success" but no order
    By RixStix in forum PayPal Express Checkout support
    Replies: 5
    Last Post: 25 Nov 2012, 06:13 AM
  3. "Forgot your password" not working
    By ekele in forum General Questions
    Replies: 3
    Last Post: 26 Jan 2011, 08:17 PM
  4. Custom "Thank You" messages on success page
    By phillip_r in forum General Questions
    Replies: 3
    Last Post: 14 Apr 2009, 09:23 PM
  5. "forgot password" freezes access
    By Schnak in forum General Questions
    Replies: 2
    Last Post: 14 Jul 2008, 05:15 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR