logoalt Hacker News

johnisgoodlast Friday at 12:44 PM1 replyview on HN

A password reset e-mail is supposed to expire pretty quickly though, so would it really matter in practice?


Replies

charcircuitlast Friday at 2:08 PM

The email must be able to be used at any time which means that and attacker may be able to also "use" them.