Hacker News new | ask | show | jobs
by crtasm 957 days ago
A lot of account compromise is due to reused passwords so I'm not sure that's a complete solution.
2 comments

Sending a PGP-encrypted email with a verification link to activate the feature should solve that.
What are the disadvantages of only signing (and not encrypting the message body of) account reset emails?
The point is that much more sensitive things exist online and it's a solved problem