New login procedure when password forgotten

Message boards : Server programs : New login procedure when password forgotten
Message board moderation

To post messages, you must log in.

AuthorMessage
Profile Jord
Volunteer tester
Help desk expert
Avatar

Send message
Joined: 29 Aug 05
Posts: 15480
Netherlands
Message 13971 - Posted: 20 Nov 2007, 1:15:34 UTC

Also posted this on the BOINC_DEV email list.

In reply to http://boinc.berkeley.edu/trac/changeset/14263

I have just tested this code on Enigma@Home (thanks to TJM for adding it temporarily to the server).
My concern is this, isn't it made more difficult now to get the authenticator key?

Don't get me wrong, I think the embedded authenticator key in the URL to click in the email you can get is a good idea, but why the whole other story on how to retrieve it from the account_*.xml file? Chances are high that I no longer have an account_*.xml file for the project. Especially not if my email address changed, which usually means I went away for a long time and am returning to this or that project. Who here keeps all his account_*.xml files for all projects as a backup? If you want to keep them available, let BOINC make a backup of the files before detaching. (which isn't such a bad idea, imho)

I understand that the only unique thing in the database is still the email address, so it needs to be used to email the authenticator key to.
But if I am really returning after a while and am no longer attached to the project, don't have a backup of the account_*.xml file and not a clue what my password could be and the email address I registered with is no longer functional, isn't it easier then to make a new account? Especially now David chose not to use the unique username ( http://boinc.berkeley.edu/trac/ticket/193).

See the new way... Ugh.
ID: 13971 · Report as offensive
Profile Saenger
Avatar

Send message
Joined: 9 Nov 05
Posts: 123
Germany
Message 13980 - Posted: 20 Nov 2007, 7:12:07 UTC
Last modified: 20 Nov 2007, 7:21:58 UTC

I think it would be handy to have this description on another but the first page to retrieve your account key (and thus ultimately your wanted password), probably linked from here with a short sentence like:

If you don't have access to your email any longer, there's perhaps a possibility to retrieve it from your computer. For instructions look here.


The whole instructions look quite nerdy on the first retrieval page imho, far too technical for a normal user who just wants his/her account key send back once more.

Edit:
Question to the mods here:
Is it necessary to post this to the mailing lists as well, as I definitely know that David doesn't use this board here or do you pass all this stuff further on to him?

Next Edit:
I just read the dev list and saw that it's already in there ;)
Gruesse vom Saenger

For questions about Boinc look in the BOINC-Wiki
ID: 13980 · Report as offensive
Profile Jord
Volunteer tester
Help desk expert
Avatar

Send message
Joined: 29 Aug 05
Posts: 15480
Netherlands
Message 13983 - Posted: 20 Nov 2007, 9:28:37 UTC - in response to Message 13980.  

I posted it here as well to have a separate discussion about it.
(Not unlike some of your posts...) :-)

To make things clearer, the image I pointed at is the second login screen option. I got there by clicking the 'forgot your password' link.
ID: 13983 · Report as offensive

Message boards : Server programs : New login procedure when password forgotten

Copyright © 2024 University of California.
Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation.