Facebook and Yahoo Find a New Way to Save the Web's Lost ...
文章推薦指數: 80 %
The problem is that email addresses are used for password recovery on sites across the web. Let's say that, a decade ago, I signed up for ... SkiptomaincontentBackchannelBusinessCultureGearIdeasScienceSecurityPodcastsVideoArtificialIntelligenceClimateGamesNewslettersMagazineEventsWiredInsiderCouponsWhenYahooproposedaplantoreusemothballedemailaddresses,alotofpeopledidn'tlikeit.WIRED'sMatHonancalledita"verybadidea,"andwithgoodreason.Theproblemisthatemailaddressesareusedforpasswordrecoveryonsitesacrosstheweb.Let'ssaythat,adecadeago,[email protected],andthatbecameawayofrecoveringmyFacebookpassword.IfIthenstoppedusingYahoo,ascammercouldwaituntilbob@yahoo.combecameavailableandthensimplytakeovermyFacebookaccount.ButFacebookandYahooarenowofferingasolutiontothisproblem,makingnewuseoftheinternet'semailprotocol,knownasSimpleMailTransferProtocol,orSMTP.They'vewrittensoftwarethatletsFacebooktimestampitspasswordrecoverymessages,showingthedatetheylastconfirmedthattheYahooaddresswaslegit.Iftheaccounthaschangedhandssincethen,Facebooksimplydropsthemessage.Thatstopspasswordresetsfromfallingintothewronghands.ThiscouldfinallyfreeupsomanyoftheemailaddressesthathavebeenleftunusednotonlyatYahoo,butatotheronlineemailproviders,includingGoogleandMicrosoft.Thetrickisthatwebsites---siteslikeFacebookthathandlepasswordrecovery---needtoadoptthisstandardforittobetrulyeffective.Weexpectthatbanksandothersecuritymindedinstitutionswilljumponboard,butnodoubt,therewillbesitesthatdon't.AndformerYahoouserswillprobablylearnaboutthemthehardway.FacebookandYahoohavealreadywrittentheirreset-checkingsoftware,butthey'vealsosubmittedtheirprotocolasapotentialextensiontothewaythatSMTPworks.They'vegivenitthesnappynameRRVS(Require-Recipient-Valid-Since).Expecttoseeitongeekt-shirtssoon.RobertMcMillancoversthecomplextechnologiesthatrunbehindthescenestomakeyourmobileappsdocoolthings.Sendhimatipatrobert_mcmillan@wired.comSeniorWriterTwitterTopicsEnterprise
延伸文章資訊
- 1Add, change, or remove a recovery method | Yahoo Help
- 2Facebook and Yahoo Find a New Way to Save the Web's Lost ...
The problem is that email addresses are used for password recovery on sites across the web. Let's...
- 3Create a Google Account
Verify your email address with the code sent to your existing email. Click Verify. Step 2: Protec...
- 4Reset or change your Yahoo password - SLN27051
Reset a forgotten password · Go to the Sign-in Helper. · Enter one of the account recovery items ...
- 5Help for your Yahoo Account
Set up, use, and manage Yahoo Account Key to sign in without a password · Fix issues with Yahoo A...