Hacker News new | ask | show | jobs
by epaga 4951 days ago
It can get way worse than that: at a big chess site I used to play at, a password reset email gives you a url of the form ".../passwordreset.php?user=yourname&password=yourfreakingpasswordincleartext" I let them know about it years ago. Nothing changed.
1 comments

Even more scary if the link isn't over ssl, but even than third party services could make it risky. http://stackoverflow.com/questions/893959/if-you-use-https-w...