Hacker News new | past | comments | ask | show | jobs | submit login

You're current password shouldn't stop working because otherwise that can be used as a denial of service without otherwise compromising the security of either the user or the site if the email address is known.



Obviously it shouldn't stop working straight away, but presumably an attacker would actually use the password reset code, at which point they would set your password to something else, which you would notice.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: