Account recovery

Sabari Devadoss sabari_d at
Thu Jan 22 01:59:16 UTC 2009

> Perhaps email is something that you have to have in order to sign up
> and access sites, but I'm not sure, again, that that's true for all
> audiences. I think more research is necessary in this area, and in
> specific applications.
> Chris

If the OP passes a verified email address via sreg or A/X then the RP can store this information and use it for AR purposes in cases where the user has forgotten the identifier used to log into the RP.  One caveat is that the email being passed by the OP should be a verified email address.   As part of the sreg testing currently underway at Yahoo! we pass the Yahoo! email address attached to the identifier which requires no additional email verification step on the RP's part.  

More information about the user-experience mailing list