Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
0 points
jrochkind1
12y ago
0 comments
Save
Share
If their policy is that support staff should
never
be able to change an accounts email address... why does the system let them do it?
0 comments
1 comments · 1 top-level
top
newest
oldest
IgorPartola
12y ago
At some point someone has direct DB access and can do this. Sure, normal support people don't but this just makes the social engineering aspect a bit more complex, not impossible.
j
/
k
navigate · click thread line to collapse