Hacker News new | ask | show | jobs
by jrussbowman 5843 days ago
or both... assign a random GUID, and then allow the user to set it something they want if they choose. That's probably the simplest way, and of course the simpler the better for both development and security.
1 comments

Surely the easiest way would be to require you put your password somewhere in the body of the email.

eg:

  Hi this is an example blog post
  I'm gonna see if this works
  ys8uc99p
I think that putting a password inside the post field (the email body) could lead to some issues. :)