Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Another very annoying one is when doing forgot password changes the password and emails you a copy, so some funny guy can just go and keep doing forgot password and it force changes your password.


I know a site that does this, except they run their own SMTP server that sometimes blocks up, so the emails never arrive.



w




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: