Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You don't store passwords on your inbox, do you? The reason is that if someone has access to your email, then you are screwed. Same applies with what this guy is proposing: I find your email password, I change it and you are screwed.


But sites that provide an "I forgot my password" already have this vulnerability if they don't ask for any further information to recover your password. Many sites don't. If someone has access to your email, you're already just as screwed.

Sites that do ask for extra info (Mother's maiden name type of thing) are protected against this, but there are an awful lot of sites that never ask you for anything but an email address and a password when signing up.


Those are the sites who are not doing their job properly and there's no reason to adapt to their solution. Getting rid of passwords tout-court may seem convenient but it's really bad for security.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: