|
|
|
|
|
by mmatants
5467 days ago
|
|
Companies like Hover have a user/password scenario unlike e.g. an email provider: users only visit their site one/two times a year (to renew a domain or whatever). So I wonder if they should instead allow "authentication-by-email". Basically, make it work just like current reset emails (with an embedded randomized link that allows access), but prevent the link from expiring. Obviously that suggestion has a lot of holes in it, too, but it's something to consider, especially since it's not a new idea. Either way, it's a real amateur move to do away with hashing. |
|