Hacker News new | ask | show | jobs
by gtCameron 2451 days ago
If you control the email address on the account you could get in by resetting the password, so I'm not sure what the difference is there
1 comments

To me the difference is the intent - I didn't intend on entering someone else's account. If I'd tried to log in with a password/email, it would have told me the account already exists, or prompted me to reset the password, and then I'd need to request that and knowingly invade the account. This way I just walked right in without even knowing what I was doing - I didn't realize there was even a problem until I went "hey, that's not my phone number!".