Edgewall Software

Opened 8 years ago

Closed 8 years ago

Last modified 8 years ago

#12425 closed defect (cantfix)

Password recovery is stupid: should ask for either username or email, not both — at Version 2

Reported by: teo8976@… Owned by:
Priority: normal Milestone:
Component: general Version:
Severity: normal Keywords:
Cc: Branch:
Release Notes:
API Changes:
Internal Changes:

Description (last modified by Jun Omae)

There are two kinds of decent "forgot your password" procedures:

  • those which ask you to enter your email
  • those which let choose whether to enter the username or the email

Asking for both is stupid (as would be asking for the username without the option to use the email instead), as one may have forgotten the username.

It's pathetic that in 2016 we still see sites that ask for both username and email for password reset.

Change History (2)

comment:1 by Jun Omae, 8 years ago

Resolution: cantfix
Severity: criticalnormal
Status: newclosed

comment:2 by Jun Omae, 8 years ago

Description: modified (diff)
Summary: Password recovery is stupid: should ask for EITHER username OR email, not bothPassword recovery is stupid: should ask for either username or email, not both

I'm guessing the reason is that multiple users can have same email address in Trac.

Note: See TracTickets for help on using tickets.