Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think a lot of people do this for infrequently visited sites, but:

1. It generates at least 3 new database transactions each time it happens, not to mention the associated crypto requirements and email.

2. This password recovery system is a common attack vector and vulnerable to social engineering attacks and MITM attacks.

3. It is mostly obviated by the existence of password managers. For those with the knowhow to do this sort of thing, all of this sort of stuff should be happening on the client side.



3) is not really useful if you login quite often from different devices that aren’t synced, so you can’t use a password manager.


well if your password manager is cloud based or each device knows of the others existence you could pull it off. I would not mind the later.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: