Hacker News new | ask | show | jobs
by packtreefly 378 days ago
> It’s surprising how something that seems harmless, like a simple recovery page, can actually hide some pretty serious security risks.

This is something you should include in any personal security checkup. Attempt account recovery using every allowed mechanism. The rules for recovery change over time in a way that classical login doesn't.