Hacker News new | ask | show | jobs
by jtchang 1349 days ago
How does this solve it? You still need to wait 1 minute.
1 comments

What security context are we talking about where that 1 minute matters?
A person has accessed your account and you’ve noticed it via sign-in-email. You change your password.

Attacker now still has 1-10 minutes to access your account.