Hacker News new | ask | show | jobs
by Dowwie 2727 days ago
How about a "Reset Buddy"?

During registration, a user adds a reset email that was different from the user's primary email. The email address is of someone you know who can give you the reset key when it is emailed to them.

With this approach, your designated reset buddy's email would have to be hacked as well then. So, even if you've been completely Pwn3d, your buddy hasn't.

1 comments

That is good approach for all invite-only and referal-based services.