Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update: Forgot Password #1538

Open
gl4nce opened this issue Nov 9, 2024 · 1 comment
Open

Update: Forgot Password #1538

gl4nce opened this issue Nov 9, 2024 · 1 comment
Labels
ACK_WAITING Issue waiting acknowledgement from core team before to start the work to fix it. HELP_WANTED Issue for which help is wanted to do the job. UPDATE_CS Issue about the update/refactoring of a existing cheat sheet.

Comments

@gl4nce
Copy link

gl4nce commented Nov 9, 2024

What is missing or needs to be updated?

The section Offline Methods contains wrong information. The real-world examples are all leading to backup codes in connection with MFA, which is out of scope of this CS.

How should this be resolved?

The Section should be removed. AFAIK, there is no secure offline method for account recovery. Instead of removing it, this could be clearly stated there.

@gl4nce gl4nce added ACK_WAITING Issue waiting acknowledgement from core team before to start the work to fix it. HELP_WANTED Issue for which help is wanted to do the job. UPDATE_CS Issue about the update/refactoring of a existing cheat sheet. labels Nov 9, 2024
@mackowski
Copy link
Collaborator

Backup Codes are listed and described as example of Offline Methods https://cheatsheetseries.owasp.org/cheatsheets/Forgot_Password_Cheat_Sheet.html#backup-codes.
I think that we should not remove it but improve. @jmanico what do you think?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ACK_WAITING Issue waiting acknowledgement from core team before to start the work to fix it. HELP_WANTED Issue for which help is wanted to do the job. UPDATE_CS Issue about the update/refactoring of a existing cheat sheet.
Projects
None yet
Development

No branches or pull requests

2 participants