#3024 - Lost-password form privacy (and assorted discussed ideas)

Identifier #3024
Issue type Feature request or suggestion
Title Lost-password form privacy (and assorted discussed ideas)
Status Completed
Tags

Roadmap: v11 (custom)

Type: Security (custom)

Handling member Chris Graham
Addon core_cns
Description On embarrassing sites someone could use the lost-password form to see if some member is registered on the site. (It could be someone else registered them and didn't activate though.).

Ideally we want to do the following:
- Send out an email to any address, saying whether there is an account or not in that email
- In the message by very generic, just say an email has been sent to the address which will initiate the reset process, if the account exists
- Add CAPTCHA to stop bots

Giving a generic response meets the privacy requirement.
Sending the email helps the user know if they are trying to reset on the wrong email address (many people use multiple addresses). / help them know if they are getting spam-filtered
CAPTCHA stops the increased spam risk.
Steps to reproduce

Funded? No
The system will post a comment when this issue is modified (e.g., status changes). To be notified of this, click "Enable comment notifications".

Rating

Unrated