H6.11

Password Recovery and Reset

Cards in this group · 4

  1. H6.11.1Recovery must not leak answers easier to guess than the password
  2. H6.11.2Reset links must expire and be single-use
  3. H6.11.3After reset, all existing sessions must be invalidated
  4. H6.11.4Recovery must not reveal whether an account exists to an unverified party