Hacker News new | ask | show | jobs
by harshitaneja 1407 days ago
Ah. I misinterpreted this thinking the user password would be used but in this case having a separate password which user would have to reenter erratically.

I am not in security but think that XSS might be a concern here with something so sensitive.

And UX problems that come with it. Sounds interesting though to at least discuss with customers to see if the benefits are worth the costs to them.