Forgot Password? Done Right: Account Recovery, the Weakest Link | Bits To Billions
Bits To Billions
0:00 / 0:00
Forgot Password? Done Right: Account Recovery, the Weakest Link | Bits To Billions
2 просмотра · 3 дня назад
Bits To Billions
16 подписчиков
2 просмотра · 3 дня назад
Account recovery - the "Forgot Password?" link - is the way back into an account when
you lose your key, and on most sites it is the weakest thing about them. This is a defender's
explainer: how to build recovery so that only the real person gets back in, and nobody else.
Maya gets home late and her keys are across town. A locksmith lets her in within thirty
seconds - after asking only her name and the address she is standing at. The next morning
she builds the little grey "forgot password?" link for her company's login, and realizes it
is that locksmith: built to let in whoever has lost their key, and whoever says the right things.
This video is about that side door. Why a reset link is a password with a short fuse, and
how to build one. Why the reset page must never reveal whether an email has an account. Why
security questions and text-message codes are the weak way back in. And how an attacker who
cannot beat the password or the second factor online simply picks up the phone and calls
support. Every load-bearing claim here was checked against a primary source.
WHAT YOU'LL LEARN
Why account recovery is a BYPASS of your password - so the account is only as strong as its weakest way back in
The reset link as a temporary credential: a cryptographically random token, at least 64 bits (NIST)
Single-use, short-lived, and stored only as a hash - so a leaked database hands out no working links
Sent only to the address on file, tied to one account; and OWASP gives no fixed lifetime (NIST: up to 24h email / 10min SMS)
On reset: no auto-login, invalidate all sessions, email the owner - and never email the password
The identical-response rule: 'If that email address is in our database, we will send you an email to reset your password'
Why a differing response is account enumeration (CWE-204) - across message, status, length, redirect AND timing (CWE-208)
Killing the timing leak with equal work (send mail asynchronously), and rate-limiting the reset endpoint
Your email is the root of recovery - so the strongest lock you own belongs on your inbox
Why security questions / KBA are deprecated (NIST 800-63B and 800-63A: SHALL NOT be used)
Why SMS codes are the weak option: SIM swap, the FBI's $68M in a year, and NIST's RESTRICTED label
Stronger recovery: authenticator apps, printed backup codes, and hardware security keys
The help desk is a recovery channel too - it must verify identity at least as strongly as the login
Never verify by facts that can be looked up; prove the person is present; require step-up for MFA resets
MFA reset as the crown-jewel action, and why it needs the strongest checks and a second approver
The 2012 Mat Honan takeover - chained phone-support recovery, and what Amazon and Apple changed
CHAPTERS
00:00 Intro
02:00 The way back in
04:02 The link in your inbox
07:16 The page that says too much
10:20 The weak ways back in
13:56 The human door
17:43 Forgot password, done right
19:28 Recap
SOURCES
OWASP Forgot Password Cheat Sheet (token properties, consistent message and timing, rate limiting, invalidate sessions, notify)
OWASP Authentication Cheat Sheet - recommended recovery message: 'If that email address is in our database, we will send you an email to reset your password.'
OWASP Web Security Testing Guide: WSTG-IDNT-04 (account enumeration) and WSTG-ATHN-09 (weak password reset)
OWASP Choosing and Using Security Questions Cheat Sheet
MITRE CWE-204 (Observable Response Discrepancy) and CWE-208 (Observable Timing Discrepancy)
NIST SP 800-63B: rate limiting; PSTN out-of-band RESTRICTED (5.1.3.3); recovery repeats identity proofing (6.1.2.3)
NIST SP 800-63B-4: no KBA or security questions (3.1.1.2); recovery codes of at least 64 bits, valid up to 24h by email / 10 min by text (4.2); binding at AAL (4.1.2.1)
NIST SP 800-63A-4: knowledge-based verification SHALL NOT be used for identity verification (2.5.1)
FBI IC3 PSA on SIM swapping (8 Feb 2022): 1,611 complaints and over $68 million lost in 2021
FTC, SIM Swap Scams: How to Protect Yourself (Oct 2019)
CISA / FBI advisory AA23-320A (Scattered Spider): help-desk social engineering to reset passwords and MFA
Mat Honan, 'How Apple and Amazon Security Flaws Led to My Epic Hacking', WIRED, Aug 2012
This is a defender's explainer. The attacks are named and defined only enough to understand the defences - there is no attack tooling, no social-engineering script, no step-by-step here. Every load-bearing claim, number and date was checked against a primary source before recording.
These are standalone explainers - one topic, one video, always from zero. Subscribe and you'll get the next one.
#accountrecovery #forgotpassword #cybersecurity #websecurity #infosec