Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
0 points
gloxkiqcza
5mo ago
0 comments
Save
Share
Password reset emails usually contain a token that expires rather quickly so unless I’m missing something, this should be a non-issue.
0 comments
3 comments · 1 top-level
top
newest
oldest
Fire-Dragon-DoL
5mo ago
· 2 in thread
But you can generate such emails with a public username
SkyPuncher
5mo ago
Yep. And if you also have access to my email, you can already look at it to figure out exactly what services I have an account with.
If you’ve pawned my email address, you can get my user names, send email reset, etc, etc.
ipaddr
5mo ago
Or the email address you have already hacked into. Why both with the username at that point.
j
/
k
navigate · click thread line to collapse