Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

While it's not common practice, I strongly believe that for particularly important services, there should be a time delay built into the reset process, so that if a user's email account is compromised in such a way that both the attacker and the victim receive the emails, the victim gets a chance to stop the reset process before any damage is done.


Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: