Hacker News new | ask | show | jobs
by sebstefan 954 days ago
Github asks you to log in again to add SSH keys in, this could've been similar

They're just looking for excuses

2 comments

A lot of account compromise is due to reused passwords so I'm not sure that's a complete solution.
Sending a PGP-encrypted email with a verification link to activate the feature should solve that.
What are the disadvantages of only signing (and not encrypting the message body of) account reset emails?
The point is that much more sensitive things exist online and it's a solved problem
What use case for FB relies on this feature?