Hacker News new | ask | show | jobs
by fiatpandas 214 days ago
Could anyone shed some light on the password reset email “hack”? I don’t really understand the attack sequence if the attacker doesn’t have access to your inbox. Even if you clicked them they don’t get access. My conclusion is trolling / annoyance.

The same thing happens to my Instagram account, which is an old 3-letter username that is desirable. I get hundreds of reset emails per month, all generated by the real service with legit outbound links.

1 comments

how much are these services wasting sending out these emails? surely some rate limiting would be sensible
What are they wasting, other than recipient time?

Hundreds of reset mails a month is probably rate limited; otherwise it would be hundreds a day.

Compared to the torrent of actual spam this is just a drop in the bucket.