Hacker News new | ask | show | jobs
by terraforming 3118 days ago
That is a very weird thing to do, and easily fixed. Just do an average of log-ins per day/week, and do not accept any reset passwords (from customer support) before that avg time has elapsed (+ an uncertainty) since the last time you checked the email.

How come they accepted the reset? Were you not logging in your account?

1 comments

I was logging into my account. I discovered and reported the incident within 45 minutes of the compromise.