Skip to content
This repository has been archived by the owner on Sep 3, 2020. It is now read-only.

Feature to force password reset #410

Open
3 tasks
jbuck opened this issue Jan 26, 2016 · 0 comments
Open
3 tasks

Feature to force password reset #410

jbuck opened this issue Jan 26, 2016 · 0 comments

Comments

@jbuck
Copy link
Member

jbuck commented Jan 26, 2016

It was recommended by Mozilla InfoSec that we implement a feature that allows us to force a password reset for all of our users in the worst-case scenario where our bcrypt'd passwords have been dumped and posted publicly.

We'll need to:

  • Implement a feature to force users to change their password
  • Implement a feature that displays a message why we're forcing people to change their password
  • Come up with a rough draft of copy that we could use in a blog post to explain what has happened
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant