Hacker News new | ask | show | jobs
by rikkus 4262 days ago
Yes. But this is the case with the current 'forgotten password' system.

Securing your email account can be done without 'only' using a password. I use 2 factor auth on my google accounts, for example.

2 comments

Forgotten password systems are supposed to use challenge questions to authenticate the user before resetting the password. (Of course, those same sites often provide a way to reset using challenge questions and without an e-mail confirmation, which is how celebrity accounts get compromised)
As do I. But I would love to see the stats on the active account (used by a real person) vs active account with 2-factor ratio on GMail. I'm willing to bet the takeup is fairly low.

As I mentioned elsewhere in the thread, I missed the password reset link point. I stand corrected.