Slacker News Slacker News logo featuring a lazy sloth with a folded newspaper hat
  • top
  • new
  • show
  • ask
  • jobs
Library
← Back to context

Comment by horsawlarway

6 months ago

So you use email/pass and the reset password email dumps right to the new party as well, because they control the MX records for the domain?

1 comment

horsawlarway

Reply

lxgr  6 months ago

That's why allowing account recovery using (exclusively) email is indeed a security problem.

Slacker News

Product

  • API Reference
  • Hacker News RSS
  • Source on GitHub

Community

  • Support Ukraine
  • Equal Justice Initiative
  • GiveWell Charities