Skip to content

Comment on 183M Gmail Passwords Leakedparent

Comments

Ignoring the backup email case as the other commentor left. In practice accounts are not immediately compromised so there is enough time to send a reset to the original user.

You could also do things like having the reset require the user to have a token that was issued before the compromise to prove you were able to authenticate before the leak happened.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.