Hacker News new | ask | show | jobs
by andrewmccall 5076 days ago
The same thing that happens now. Malicious user can recover/reset their password.

I'd assume that if you used the email to login and since the article talks about also using cookies with expiry dates in the future the codes in emails would be single use.