Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If the person can't read the email, then they can't read the key.

This is exactly how credential reset works on every system with registered backup email address, include Google.

The only risk is if they send the key to the wrong email address, such as From and Reply-To.



> If the person can't read the email, then they can't read the key.

You’re sending them your public key, not receiving a private key.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: