Skip to content

Comment on Password recovery procedure idea

Comments

Instead of a friend's email, why not have a second email address of yourself where the PIN is sent. Of course, hopefully the passwords of both emails are different :). Sort of like ATM card and PIN sent in separate mails in the US. I don't think adding a friend's email will be a good idea especially if i want to reset in the middle of the night as someone mentioned.

I think "no password reuse" is an over-optimistic pipe dream for most users; also, it's unlikely that two people will be compromised at once by the same (not specifically targeted) attack; a compromise of all accounts of the same person is much more likely.

Indeed - that is exactly what went wrong in the case of our unfortunate Wired reporter.

Also, there's a big chance of course that if someone has lost the password to a services he uses more or less regularly, he'll also not be able to remember the password of a service (the secondary mail account) he uses almost never ...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.