Envisaging Wyatt Lyon Preul

Those are my eyes staring at you. They allow me to see you clearly through this screen. No, don't click there, it will take you away from my online space.

Let me start again, I am Wyatt and I am a software engineer. I am also a process theologian, author, music hipster, struggling artist who enjoys thinking outside of your finitude. I am not as pretentious as that line makes me sound. If you have some spare time read more about me.

Security Tip: Require Original Password to Change Password

A A A

I logged into my account at Wachovia with plans to change my password.

  It is a good idea, I believe, to periodically change your passwords, especially passwords related to financial accounts.  When I went to the change password page, Wachovia didn't ask me my original password, but instead only asked for a new password, and to confirm my new password.

This is a bad practice to not ask for the original password because this allows for someone to deny me access to my account without even needing my password.  If they were able to hijack my session, for example, they could change my password and now have complete ownership of my account.

So my tip to you is, make sure you ask for the original password before allowing a user to change a password.