In 2008, over one thousand people experienced the world’s first virtual web conference. Together, we created a new type of conference that is environmentally-friendly, affordable, and interactive.

In 2009, we are going to take it one step further.


LOVEFILM forgotten password antipattern

If you really want to annoy someone on LOVEFILM, enter their email address in the "Forgotten Password" screen.

Here's what happens:

  1. LOVEFILM immediately changes the user's password
  2. LOVEFILM emails the user with a new, random password and asks them to log in with that new password.

If you're the poor sap at the receiving end of this prank, you have to:

  1. Log in with your new password
  2. Go to your account and change your password

They've got this whole "forgotten password" pattern all wrong.

Here's how it should work:

LOVEFILM should send you a temporary password (e.g. valid for an hour) that you can log in with but it shouldn't disable/change your current password. That way, if someone else requested the change (either by mistake or to annoy you), you can simply ignore the email.

The way it's implemented today, LOVEFILM actually allows a random stranger to make a change to your account (change your password) and causes you to take steps to remedy that action.

If someone wanted to really piss you off, they could reset your password daily.

I only stumbled upon this because I thought I had forgotten my password and requested a new one. Then, before the email arrived, I remembered my password. But it was too late. LOVEFILM had changed my password the moment I'd entered my email address in (and so I had to wait for the email to arrive before I could login to my account).

Of course, they could also side-step all this and implement support for OpenID. That would really rock!

Post Metadata

Date
March 22nd, 2008

Author
Aral

Category


1 Trackbacks & Pingbacks

  1. March 23, 2008 12:24 pm

    Hendrik Mans » LOVEFILM forgotten password antipattern :

7 Comments


  1. Anonymous prick

    So…. what’s your email address?



  2. That is pretty stupid indeed, I don’t understand why openID is so rarly used…

    But Aral, weren’t you a Flashprogrammer? You only write about other stuff :) (not that it is not interesting but I’d love some more swx…)


  3. Reminds me of very similar functionality in the popular web based Project Management solution, ProjectPier. If you just so happen to know the email address of any user in the system, you can quite simply reset their password via the “Forgot Password” screen.

    Absolutely ridiculous, imo.



  4. Jon

    At least you know that they are encrypting your password.

    Too many websites store passwords in clear text and simple email you your existing password if you hit the “forgot password” button.



  5. mad_dog

    Hi,

    Actually this mechanism for password resets (sending a reset to your registered email address) is fairly common on the web. Some sites are even silly enough to send the existing password in the clear, rather than a random reset.

    I guess that I could sign up for tons of spam using your email address but would you complain that there was a flaw in such a system? If I know your email address and want to cause hassles for you, there are more inventive ways of annoying you than resetting your lovefilm ID.

    Much more important is how personal details are protected! I’d worry more about that than a password reset. As a means of DOS attack, it would be pretty lame and easily spotted.



  6. Simon

    Whats even more annoying is there doesn’t currently seem to be a way to change your password once it has been reset.

    This has had me looking on the website for quite a while. Its in none of the obviously places.


Leave a Reply



Bad Behavior has blocked 0 access attempts in the last 7 days.