Skip to content
This repository has been archived by the owner on Jul 24, 2021. It is now read-only.

Saving new passwords does not require the old one #5129

Closed
openstreetmap-trac opened this issue Jul 23, 2021 · 5 comments
Closed

Saving new passwords does not require the old one #5129

openstreetmap-trac opened this issue Jul 23, 2021 · 5 comments

Comments

@openstreetmap-trac
Copy link

Reporter: oxplot
[Submitted to the original trac issue database at 1.04am, Monday, 24th February 2014]

When saving a new password under [[https://www.openstreetmap.org/user/username/account|User Account Settings]] page, the old password is not required.

This is very bad. A malicious party who has stolen a logged in session can take away access from the original user completely by changing his/her password.

@openstreetmap-trac
Copy link
Author

Author: TomH
[Added to the original trac issue at 9.02am, Tuesday, 25th February 2014]

They can't actually take away access completely, because the user can still recover access using the password reset facility - the only way to stop that would be to change the email, but you can't do that without access to the original email in order to confirm the change.

@openstreetmap-trac
Copy link
Author

Author: oxplot
[Added to the original trac issue at 3.04pm, Tuesday, 25th February 2014]

What if someone lost access to their original email and wanted to change their email to a new one?

@openstreetmap-trac
Copy link
Author

Author: TomH
[Added to the original trac issue at 3.06pm, Tuesday, 25th February 2014]

The only way to do that is to contact support and have us do it by hand if you can convince us it really is your account.

@openstreetmap-trac
Copy link
Author

Author: oxplot
[Added to the original trac issue at 3.15pm, Tuesday, 25th February 2014]

OK, then room for improvement. If the old password is required for setting a new one, you:

  • Fix the issue here (it's still an issue because it creates work for the user)
  • Reduce the number of support calls and the headache of figuring out if someone's telling the truth or not.

And users can still forget and reset their passwords like before.

@openstreetmap-trac
Copy link
Author

Author: mmd
[Added to the original trac issue at 12.36pm, Friday, 21st June 2019]

Discussion continues here: openstreetmap/openstreetmap-website#2144

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

1 participant