Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well spotted - I kind of mangled that explanation. The risk being mitigated is if somebody gets a dump of your old emails. Short-lived reset tokens don't help if they have full access to you email account.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: