Hacker News new | ask | show | jobs
by DrScump 3797 days ago
Registration rejects email addresses with certain characters ("+" at least)

Also, I think it's a bad idea to offer common financial codes as recovery codes for your site (SSN, mother's maiden name, etc.)

1 comments

Thank you, DrScump. Both of these have been fixed. Users will be warned to change their security question if they're using an old, insecure question type, and no one will be able to select those questions beginning immediately. I was using a standard list of security questions, but I absolutely see the value of avoiding such info.