It's kind or ridiculous to set up any security beyond accessing a forum account for login passwords. Wouldn't it be kind of easy just to copy the forum password field data into the login password field data in a SQL table upon requesting a "password reset"? I'm assuming they're both in the same type of encryption. Like the man said, if someone has access to their forum account (like me) they should be the owner. It's not like you're holding billions of EQLive Plat on a mule here nor any super secret squirrel stuff.
|