keybase / keybase-issues

A single repo for managing publicly recognized issues with the keybase client, installer, and website.
899 stars 37 forks source link

Password recovery guard time is too short #2331

Open smurfix opened 8 years ago

smurfix commented 8 years ago

Your password recovery email takes too long to arrive in my inbox.

Return-path: <REDACTED@amazonses.com>
Envelope-to: matthias@urlichs.de
Delivery-date: Sun, 03 Jul 2016 13:54:05 +0000
Received: from a8-176.smtp-out.amazonses.com ([54.240.8.176])
    by netz.extern.smurf.noris.de with esmtps (TLS1.0:ECDHE_RSA_AES_128_CBC_SHA1:128)
    (Exim 4.87)
    (envelope-from <REDACTED@amazonses.com>)
    id 1bJhpv-0003s1-J6
    for matthias@urlichs.de; Sun, 03 Jul 2016 13:53:37 +0000
From: "Keybase.io" <notify@keybase.io>
To: matthias@urlichs.de
Subject: Reset Your Password
Date: Sun, 3 Jul 2016 13:35:25 +0000

By the time I actually manage to check my Inbox, it has expired.

Your authentication token was corrupted in transit; please try again.
(Failed MAC check: Error: for uid REDACTED,matthias@urlichs.de: Expired 425s ago)

Please extend that timeout to at least an hour.

-- Matthias Urlichs

glensc commented 7 years ago

same here, graylisting in front of my mailbox may hold up to 30 minutes email until it reaches my inbox!

suggested expiry: 60 minutes!

quietsche commented 7 years ago

same here. please fix