Hacker News new | ask | show | jobs
by londons_explore 1477 days ago
You have to deal with 'email antivirus scanners' which click every link in a mail sent to every user in some sandboxed browser.

If your user has one of those, then their account effectively has zero security since an attacker can attempt to log in, and the web security software will click the link, and the attacker (in the originating browser) is now logged in.

1 comments

Those destroy the links anyway; I can never reset a Salesforce password because the link is always “expired”.