Hacker News new | ask | show | jobs
by oneeyedpigeon 3524 days ago
That should definitely happen anyway but, as the article points out, that leaves a window of time between the user clicking the link in their email and them completing the form. It might be a very brief window, but it's still exploitable (and it won't always be brief - consider a user clicking the link in their email, leaving their desk for 5 minutes or going to make a cup of tea...)
1 comments

Not to mention the users that will request a reset but then remember, or forget to follow up with the reset (which I myself have been guilty of in the past).