Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's also worth considering threat models. It may be worth risking account takeover if they can keep the reset flow user friendly. Not every site needs bulletproof security, this one seems lower risk.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: