How to reset mysql password without old password?

Great password reset UIs?

odinsdream at Ask.Metafilter.Com Visit the source

Was this solution helpful to you?

Other answers

For me, the canonical "doing it wrong" account management belongs to http://www.centrelink.gov.au/internet/internet.nsf/home/index.htm At present, I can't even exercise the "register an account" function from that page because all paths through the maze end up at a "successfully logged out" page. That may change tomorrow. Resetting your password can only be done if you have previously created at least three "security questions" (of which you can create up to twenty IIRC). Why you need three is mysterious to me; you only have to get two of them right. Passwords must be exactly eight characters, are checked to make sure they contain at least one lowercase character, at least one uppercase character, and at least one digit. And if you try to use something like KeePass to create these and then paste them in, you get a pop-up window about functions being disabled and your clipboard gets cleared; persist, and you eventually get the option not to be told about that again, at which point pasting starts to work. But if your new password fails validation, the anti-paste pop-up thing starts again. And if you have created any security questions, you need to answer one of them correctly on every logon attempt. And there's a minimum-length limit on security question answers too, so it's just too bad if your first pet's name was "Rex". Other terrible practices I've seen from other sites: - sending emails including your password in plain text (variations: do this for initial passwords only, not for password changes; do this for "temporary" passwords after password resets; do this for password recovery, indicating that the server is holding your actual password rather than a salted hash of it). - no way to change password after logging in - closest is a "forgot password" facility available only before logging in (Simply Energy's old web site did this). Best account-creation facility I've ever used is Google's. About the only thing wrong with it is that the password strength meter is far, far too lenient about what it considers "strong"; there's clearly no attempt at all to derate passwords containing dictionary words.

flabdablet

I'm a big fan of how https://lastpass.com/ deals with passwords, both for the site itself and the way it stores passwords for other sites. I think the canonical example of what not to do is PayPal.

dfriedman

Regarding lastpass; I appreciate their service and we use it extensively, but we're looking for UI options for a self-contained system, so no OpenID, or "Login with Facebook" or Google Apps, etc., as nice as those are.

odinsdream

I found the user registration process at http://www.rdio.com to be slicker than usual. In particular, it only asks you for your email address at first, and then combines the email confirmation step with the remainder of the registration.

maxim0512

Funny, just last week I noticed how slick that Facebook's password reset is if you use Gmail.

rhizome

Related Q & A:

Just Added Q & A:

Find solution

For every problem there is a solution! Proved by Solucija.

  • Got an issue and looking for advice?

  • Ask Solucija to search every corner of the Web for help.

  • Get workable solutions and helpful tips in a moment.

Just ask Solucija about an issue you face and immediately get a list of ready solutions, answers and tips from other Internet users. We always provide the most suitable and complete answer to your question at the top, along with a few good alternatives below.