Hacker News new | ask | show | jobs
by kvs 5659 days ago
Why is this better than current approach? Is it because the current password remain unchanged until the user click on the link to reset part?
1 comments

Exactly. It allows people to easily reset their passwords if they've forgotten them while reducing their need to update their password if someone accidentally/maliciously attempts a reset.