Hacker News new | past | comments | ask | show | jobs | submit login

This only happens if SMS get's used in the password-recovery workflow. I don't think there is evidence that TD is using SMS to replace password reset.

So I really don't see how this makes security worse.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: