Hacker News new | ask | show | jobs
by pc86 1022 days ago
Not if you have multiple email accounts. Many times these codes reset in just a few minutes, you should try to avoid forcing users to spend time logging into every single email they can remember just to wait for an email to pop into one of them. You can show a few characters of an email or the first character of the domain to give a lot of info out in relative safety.

Everything is about tradeoffs, and the only objectively wrong answer is this dogmatic "never do $X" nonsense.