Password Reset Alternatives

Discussions center on challenges and alternatives to email-based password resets, including how to handle account recovery without email or phone access, and comparisons to standard recovery methods like security questions.

📉 Falling 0.3x Security
3,791
Comments
20
Years Active
5
Top Authors
#1997
Topic ID

Activity Over Time

2007
15
2008
50
2009
96
2010
88
2011
225
2012
292
2013
250
2014
246
2015
162
2016
258
2017
236
2018
228
2019
243
2020
221
2021
258
2022
336
2023
214
2024
196
2025
170
2026
7

Keywords

e.g clef.io twitter.com OK ANY AWS BEFORE GET gitlab.com PIN password reset email account recovery phone number passwords mail phone security

Sample Comments

codingkev Feb 20, 2022 View on HN

What do you suggest as an alternative to password reset based on the account email?

mattl Mar 24, 2023 View on HN

How do you propose password resets work without an email address or phone number?

SpelingBeeChamp Sep 14, 2022 View on HN

Why didn't you just require password resets to be done by the user?

vbuterin Mar 31, 2013 View on HN

Why can't they just use email password recovery like everyone else?...

testplzignore Apr 10, 2018 View on HN

I've lost an account on another service this way. They did a forced password reset. To set a new password, you had to go through the forgot password flow, receive the email, and then answer the security questions. You would think that if the passwords were compromised, the (probably plain text) security questions were certainly compromised.

danenania Jan 8, 2025 View on HN

With password reset, you are also trusting email.

felisml Jul 2, 2017 View on HN

If you're allowing emails as a credential reset mechanism, you've already got that problem.

blinded Aug 15, 2024 View on HN

how else do you expect they send you password resets?

nodata Sep 2, 2014 View on HN

Why is nobody talking about password reset questions?

Sir_Cmpwn Dec 6, 2018 View on HN

Most services have a mechanism through which you can reset your password, usually email. Losing access to your password store isn't the end of the world.