{"ok":true,"trend":{"id":599259,"platform":"mastodon","region":"global","key":"account recovery is the weak link, and i think the framing is off. nist 800-63-4 and owasp asvs require notifying the ow","title":"Account recovery is the weak link, and I think the framing is off. NIST 800-63-4 and OWASP ASVS require notifying the ow","url":"https://infosec.exchange/@simontennyson/117365161164351337","first_seen":"2026-10-01T10:47:26.870821Z","last_seen":"2026-10-01T10:47:26.870821Z","last_rank":12,"peak_rank":12,"last_volume":1,"peak_volume":1,"seen_count":1,"score":48.54,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A security practitioner argues that account recovery flows remain the weakest link in authentication, and that the framing around them is wrong. Standards like NIST 800-63-4 and OWASP ASVS require notifying an account owner only after a password reset completes, staying silent at the attempt stage to prevent account enumeration. The practitioner contends the reset attempt itself is the one event no standard requires services to flag, leaving users blind to attacks in progress.","why":"Renewed attention on NIST 800-63-4 has reignited debate over whether current account recovery notification requirements leave users exposed.","tone":"neutral","entities":["NIST","OWASP","NIST 800-63-4","OWASP ASVS"],"summarized_at":"2026-10-01T10:49:35.020572Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1291},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Security experts debate account recovery notification rules","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-01T10:47:26.870821Z","rank":12,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@simontennyson/117365161164351337","author":"simontennyson@infosec.exchange","title":null,"snippet":"Account recovery is the weak link, and I think the framing is off. NIST 800-63-4 and OWASP ASVS require notifying the owner AFTER a reset, and staying silent at the attempt. That is right for anti-enumeration. The cost: the reset attempt is the one event no standard requires…","posted_at":"2026-10-01T10:23:57Z","likes":1}],"elsewhere":[],"window":"7d"}}