Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If an email account can be used for password reset, a compromised email account can be used to log in. Since much of the internet already works this way, the proposed system has a neutral effect on security, while making things easier for users.

In effect, any site that offers a password reset via email is already using your email as your identity.



I actually use this as the primary authentication mechanism for sites I rarely/occasionally visit... password reset at every login!




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: