Hacker News new | ask | show | jobs
by raganwald 5467 days ago
If the password reset function sends a temporary password just as you say, THEN it is not that big a deal. On the other hand, if they are storing every user's original password in such a way that they send the user their existing password...

I believe this is the scenario most people here think is happening.

1 comments

Oh, I'm sure it is. I'm saying that they should send a temporary password instead.