I have an online registry of professionals with approximately 300 members. These are smart people, but not technical. Currently, if someone forgets their email address, the system sends it to their email address.
The problem is that people change their email addresses over time, then forget their password and cannot receive a reminder.
I need to create a simple authentication system that allows people to recover their passwords even if they change their email address.
I try my best to come up with everything that is even moderately safe, that does not require users email address.
Can anyone suggest something?
source
share