Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is quite common in large online games where accounts often sit unused, having only a few hours of total hours logged over years.


This is a great strategy for gaming systems, a terrible strategy for accounts used as identity management and password recovery vectors.

Let's say JamesSmith@yahoo.com used this email address long ago as his ebay recovery address, but really doesn't use his @yahoo account any more. I can register JamesSmith@yahoo.com, and use ebay's account recovery option to assign the ebay account a new password for an ebay account I have now stolen.

This scenario isn't possible with an online game account name, as game accounts aren't used to recover bank passwords or other important account passwords.


Yes, but its unlikely that an online game account was associated as the password reset contact account for confidential financial/banking websites.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: