Hacker News new | ask | show | jobs
by mathijs 4908 days ago
Ironically enough, I went to log in to HN specifically to upvote comments in this thread, forgot my password and had to use the 'email yourself a new password' function.

Granted, it sends a randomly generated password. And granted: it's probably meant for one-time use only (I presume). However, logging in with the new password does not automatically prompt (or even force) to change it to something of my own choosing. Result: hit 'remember password' in Chrome and forget about it. Now my active HN password is in my inbox, in plain text.