Support

UNiTE, Remote CLI, eXtract Wizard

#31545 Login Guard SMS forgot password

Posted in ‘UNiTE and Remote CLI’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

PHP version
n/a
Tool
UNiTE
Tool version
n/a

Latest post by on Saturday, 17 August 2019 17:17 CDT

bom
Hi, is it possible to set up Login Guard for sending a "forgot password" SMS to the registered phone of the user instead of an email? Thanks.

nicholas
Akeeba Staff
Manager
No. This has nothing to do with what LoginGuard is supposed to do. I would also say that you will probably not find any extension that can do that because it's a bad, impractical and impossible to implement idea:
  • The email sending functionality for password resets is hardcoded in Joomla's com_users code. While a developer could conceivably write a plugin to also send an SMS message it would not be able to only send the SMS message instead of the email.
  • Joomla requires a 32 character long alphanumeric code for resetting passwords as a matter of security. It would be impractical to send it by SMS and ask the user to type it.
  • Overriding Joomla's password reset is conceivable with some trickery in some, but not all, circumstances. In this case a misguided developer could conceivably replace the reset token with a short lived, six digit code BUT this would make all accounts on the site susceptible to SIM swap attacks and plain old guessing (you'd have 2-10 minutes to guess the 6-digit code which is plenty of time). The reason this is not a massive issue for 2SV is that 2SV is used on top of a username and password not instead of.


So even if you could I would say that 100% you should absolutely and definitely NOT think about implementing such a feature. It would essentially replace all passwords with a 6-digit PIN which is trivial to hack. I understand what you had in mind but the law of unintended consequences applies very strongly to your idea. Sorry :(

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

bom
Thank you Nic. Your extensive and in depth explanation put a clear picture about the situation in my head. Again your expertise is priceless, thank you for your time!

nicholas
Akeeba Staff
Manager
No problem :) Have a great day!

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!