Hacker News new | past | comments | ask | show | jobs | submit login

I don't think it's a good idea to make a password reset take 3 entire days. In this case, I'd say the costs outweigh the benefits.



Yea, 10 minutes & a text message would suffice, IMO...


I think the most important part would be to give someone time to vet that it's legitimate. Stack Exchange has on the order of 100 developers, it wouldn't be hard to CC account creation or password reset notices to the manager of a new hire, and in that case, 10 minutes would often be enough to say "Uh, I haven't hired anyone named Curious Llama, who are they and why are they requesting developer access to an obsolete resource?" and put the brakes on.


That might not have helped in this case, if the email was sent from the same account.

The hacker had access to messages from the sender side without access to the account being reset.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: