Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A password reset e-mail is supposed to expire pretty quickly though, so would it really matter in practice?




The email must be able to be used at any time which means that and attacker may be able to also "use" them.



Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: