(Idea) Send Annual Security Reminder Emails #883

Open
opened 2024-05-16 17:15:24 +02:00 by hrmo · 1 comment

It would be nice if the system automatically sent an email at least once a year reminding each user how their account is currently set up for passwords. This will give them a chance to review their security questions, or their backup email address.

Forgotten passwords pose a substantial danger in environments where admins cannot retrieve/reset accounts, and it is only human to forget details that one entered years ago.

It would be nice if the system automatically sent an email at least once a year reminding each user how their account is currently set up for passwords. This will give them a chance to review their security questions, or their backup email address. Forgotten passwords pose a substantial danger in environments where admins cannot retrieve/reset accounts, and it is only human to forget details that one entered years ago.
Owner

One one hand yes nice idea but I wonder if this will not be seen as spam or make people less alert when getting actual spam. There is plenty of such spam emails flaying around the net and disroot users also sometimes get those phishing mails (like "your account needs update change or it will be blocked etc). Currently until rolling out new authentication system/self service center I wouldn't do anything like this. At least as long as we plan and hope to roll new auth system in near future. If we fail to deliver on this (or have at least work on advanced level) we could re-open this.
I will put it on hold for now, so we can check it when time's relevant.

One one hand yes nice idea but I wonder if this will not be seen as spam or make people less alert when getting actual spam. There is plenty of such spam emails flaying around the net and disroot users also sometimes get those phishing mails (like "your account needs update change or it will be blocked etc). Currently until rolling out new authentication system/self service center I wouldn't do anything like this. At least as long as we plan and hope to roll new auth system in near future. If we fail to deliver on this (or have at least work on advanced level) we could re-open this. I will put it on hold for now, so we can check it when time's relevant.
muppeth added the
on hold
label 2024-05-28 21:21:41 +02:00
Sign in to join this conversation.
No Milestone
No project
No Assignees
2 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: Disroot/Disroot-Project#883
No description provided.