Hacker News new | ask | show | jobs
by maxmcd 5231 days ago
While I see that is solves some issues I actually know few non-tech web users that keep their email constantly open. Implementing this would also remove the convenience of password saving tools.

Also, if all you need is an email to log in, if my email is compromised I have little to no indication that the offender has logged into that service if they delete the email. With the current web standards, if someone reset my password vie email I would no longer be able to log into the account. With your suggestion, my email could be compromised, services could be logged into and I would have no indication.

Some of these problems could be solved, but I'd say the biggest problem now is that it's very far removed from typical web standards.

1 comments

Good points, especially about no longer being able to log into the account with old password because of a forced password change.