Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For this reason, the link/code being sent should have an expiration attached to it, as well as being single-use.

This doesn't avoid any number of different scenarios.

Too bad we don't all use PGP for email...



If users could be trusted to maintain a key pair (PGP), then we wouldn't need to use email to do authentication.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: