rd reset, are you comfortable with</div><div>this bei=
ng circumvented by someone who is able to present a</div><div>convincing =
image of a utility bill to <a href=3D=22mailto:support=40bitfolk.com=22>s=
upport=40bitfolk.com</a>=3F</div><div><br></div><div>Perhaps you can offe=
r some guidelines for how this should be dealt</div><div>with in future s=
o that there can be a consistent response.</div><div><br></div><div>Sugge=
stions revolving around the customer identifying themselves</div><div>usi=
ng public key crypto (PGP keys, SSH keys) are fine but do bear in</div><d=
iv>mind that most customers have not presented either a PGP nor SSH key</=
div><div>to me, and that would have to be done before it was actually nee=
ded.</div><div><br></div><div>I could require that an SSH and/or PGP key =
be uploaded to the panel</div><div>before the panel allows you to disable=
email password resets, though</div><div>there would still need to be a p=
lan in place for the inevitable case</div><div>where the customer claims =
to no longer have access to any of the</div><div>keys they have uploaded.=
</div><div><br></div><div>Cheers,</div><div>Andy</div><div><br></div><div=
>-- </div><div><a href=3D=22http://bitfolk.com=22>http://bitfolk.com</a>/=
-- No-nonsense VPS hosting</div></div><div><div>=5F=5F=5F=5F=5F=5F=5F=5F=
=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=
=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F</div><div>users mailing list</=
div><div><a href=3D=22mailto:users=40lists.bitfolk.com=22>users=40lists.b=
itfolk.com</a></div><div><a href=3D=22https://lists.bitfolk.com/mailman/l=
istinfo/users=22>https://lists.bitfolk.com/mailman/listinfo/users</a></di=
v></div></div></span>
=20
=20
=20
=20
</blockquote>
=20
<div>
<br>
</div>
--4ff8656c_b37e80a_8726--
From aaron@??? Sat Jul 07 16:44:50 2012
Received: from phoenixsupport.org ([2001:ba8:1f1:f1de::f5:c]
helo=server02.filesanctuary.net)
by mail.bitfolk.com with esmtp (Exim 4.72)
(envelope-from <aaron@???>) id 1SnY7m-0007qP-Ci
for users@???; Sat, 07 Jul 2012 16:44:50 +0000
Received: from [192.168.0.10]
(cpc1-stkn14-2-0-cust232.11-2.cable.virginmedia.com [86.30.8.233])
by server02.filesanctuary.net (Postfix) with ESMTPSA id 5FBA58A2A5;
Sat, 7 Jul 2012 17:38:14 +0100 (BST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=unadopted.co.uk;
s=2012; t=1341679094;
bh=a6yLWV6/762FXp7LtQzqo5dNoQQrUzTMQTi19SREQhE=;
h=Date:From:To:Cc:Message-ID:In-Reply-To:References:Subject:
MIME-Version:Content-Type;
b=hlFJW4TBqiEWm6DoZjxkfnH2oCilBigYhCh9LhC4HyuTX2j+ZqCcbsMIyXlMuPyKb
POOTufUPzzi6DLraeolAsH8t7dTtep0Gsd0mXs5ev/adbLvG4tSrbA8ZQxEPeZZfzL
abxtBPf7aUNxudstYjIdcE+8SMKXjCZptTVTLnnI=
Date: Sat, 7 Jul 2012 17:38:13 +0100
From: "Aaron B. Russell" <aaron@???>
To: Andy Smith <andy@???>
Message-ID: <E8D012CEB3584285925AD3F1476D118B@???>
In-Reply-To: <ECAE67DBAB7C44C2BA99DA232CC6E395@???>
References: <20120707130537.GA11695@???>
<ECAE67DBAB7C44C2BA99DA232CC6E395@???>
X-Mailer: sparrow 1.6.1 (build 1081.52)
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="4ff865f5_7dff9d09_8726"
X-Virus-Scanner: Scanned by ClamAV on