<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: LOVEFILM forgotten password antipattern</title>
	<atom:link href="http://aralbalkan.com/1256/feed" rel="self" type="application/rss+xml" />
	<link>http://aralbalkan.com/1256</link>
	<description>Changing the world through technology and oratory.</description>
	<pubDate>Thu, 20 Nov 2008 17:36:09 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7-beta2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Simon</title>
		<link>http://aralbalkan.com/1256/comment-page-1#comment-166783</link>
		<dc:creator>Simon</dc:creator>
		<pubDate>Mon, 14 Jul 2008 18:58:29 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/1256#comment-166783</guid>
		<description>Whats even more annoying is there doesn't currently seem to be a way to change your password once it has been reset.

This has had me looking on the website for quite a while. Its in none of the obviously places.</description>
		<content:encoded><![CDATA[<p>Whats even more annoying is there doesn&#8217;t currently seem to be a way to change your password once it has been reset.</p>
<p>This has had me looking on the website for quite a while. Its in none of the obviously places.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mad_dog</title>
		<link>http://aralbalkan.com/1256/comment-page-1#comment-130130</link>
		<dc:creator>mad_dog</dc:creator>
		<pubDate>Thu, 27 Mar 2008 09:18:53 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/1256#comment-130130</guid>
		<description>Hi,

Actually this mechanism for password resets (sending a reset to your registered email address) is fairly common on the web.  Some sites are even silly enough to send the existing password in the clear, rather than a random reset.

I guess that I could sign up for tons of spam using your email address but would you complain that there was a flaw in such a system?  If I know your email address and want to cause hassles for you, there are more inventive ways of annoying you than resetting your lovefilm ID.

Much more important is how personal details are protected!  I'd worry more about that than a password reset.  As a means of DOS attack, it would be pretty lame and easily spotted.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Actually this mechanism for password resets (sending a reset to your registered email address) is fairly common on the web.  Some sites are even silly enough to send the existing password in the clear, rather than a random reset.</p>
<p>I guess that I could sign up for tons of spam using your email address but would you complain that there was a flaw in such a system?  If I know your email address and want to cause hassles for you, there are more inventive ways of annoying you than resetting your lovefilm ID.</p>
<p>Much more important is how personal details are protected!  I&#8217;d worry more about that than a password reset.  As a means of DOS attack, it would be pretty lame and easily spotted.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon</title>
		<link>http://aralbalkan.com/1256/comment-page-1#comment-129434</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Tue, 25 Mar 2008 00:25:12 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/1256#comment-129434</guid>
		<description>At least you know that they are encrypting your password.

Too many websites store passwords in clear text and simple email you your existing password if you hit the "forgot password" button.</description>
		<content:encoded><![CDATA[<p>At least you know that they are encrypting your password.</p>
<p>Too many websites store passwords in clear text and simple email you your existing password if you hit the &#8220;forgot password&#8221; button.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hendrik Mans &#187; LOVEFILM forgotten password antipattern</title>
		<link>http://aralbalkan.com/1256/comment-page-1#comment-129000</link>
		<dc:creator>Hendrik Mans &#187; LOVEFILM forgotten password antipattern</dc:creator>
		<pubDate>Sun, 23 Mar 2008 11:24:28 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/1256#comment-129000</guid>
		<description>[...] LOVEFILM forgotten password antipattern. There are sites out there that still do that? Weird. [...]</description>
		<content:encoded><![CDATA[<p>[...] LOVEFILM forgotten password antipattern. There are sites out there that still do that? Weird. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Urquhart</title>
		<link>http://aralbalkan.com/1256/comment-page-1#comment-128804</link>
		<dc:creator>James Urquhart</dc:creator>
		<pubDate>Sat, 22 Mar 2008 22:35:02 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/1256#comment-128804</guid>
		<description>Reminds me of very similar functionality in the popular web based Project Management solution, ProjectPier. If you just so happen to know the email address of any user in the system, you can quite simply reset their password via the "Forgot Password" screen.

Absolutely ridiculous, imo.</description>
		<content:encoded><![CDATA[<p>Reminds me of very similar functionality in the popular web based Project Management solution, ProjectPier. If you just so happen to know the email address of any user in the system, you can quite simply reset their password via the &#8220;Forgot Password&#8221; screen.</p>
<p>Absolutely ridiculous, imo.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jankees</title>
		<link>http://aralbalkan.com/1256/comment-page-1#comment-128796</link>
		<dc:creator>jankees</dc:creator>
		<pubDate>Sat, 22 Mar 2008 21:59:36 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/1256#comment-128796</guid>
		<description>That is pretty stupid indeed, I don't understand why openID is so rarly used... 

But Aral, weren't you a Flashprogrammer? You only write about other stuff :) (not that it is not interesting but I'd love some more swx...)</description>
		<content:encoded><![CDATA[<p>That is pretty stupid indeed, I don&#8217;t understand why openID is so rarly used&#8230; </p>
<p>But Aral, weren&#8217;t you a Flashprogrammer? You only write about other stuff <img src='http://aralbalkan.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> (not that it is not interesting but I&#8217;d love some more swx&#8230;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aral</title>
		<link>http://aralbalkan.com/1256/comment-page-1#comment-128777</link>
		<dc:creator>Aral</dc:creator>
		<pubDate>Sat, 22 Mar 2008 21:13:27 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/1256#comment-128777</guid>
		<description>LOL</description>
		<content:encoded><![CDATA[<p>LOL</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous prick</title>
		<link>http://aralbalkan.com/1256/comment-page-1#comment-128771</link>
		<dc:creator>Anonymous prick</dc:creator>
		<pubDate>Sat, 22 Mar 2008 21:02:59 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/1256#comment-128771</guid>
		<description>So.... what's your email address?</description>
		<content:encoded><![CDATA[<p>So&#8230;. what&#8217;s your email address?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
