Allow to upload a PGP public key, and reset request page would just return an encrypted PGP message containing a link to reset the password.
Assumes:
- people are less likely to lose their PGP key, than random password to a random website.
- people have PGP keys
- PGP key doesn't contain email address (it does).
Anyway, it would be reliable, and it doesn't need giving third party online service access to all your online accounts.
Assumes: - people are less likely to lose their PGP key, than random password to a random website. - people have PGP keys - PGP key doesn't contain email address (it does).
Anyway, it would be reliable, and it doesn't need giving third party online service access to all your online accounts.