Y
Hacker News
new
|
ask
|
show
|
jobs
by
gloxkiqcza
155 days ago
Password reset emails usually contain a token that expires rather quickly so unless I’m missing something, this should be a non-issue.
1 comments
Fire-Dragon-DoL
155 days ago
But you can generate such emails with a public username
link
SkyPuncher
155 days ago
Yep. And if you also have access to my email, you can already look at it to figure out exactly what services I have an account with.
If you’ve pawned my email address, you can get my user names, send email reset, etc, etc.
link
ipaddr
155 days ago
Or the email address you have already hacked into. Why both with the username at that point.
link