20 ms·
I'm not sure if this is actually a problem? You wouldn't share your password-recovery e-mail with anyone either? I guess it's not the best thing to do (and not
by provito 13y ago
I'm not sure if this is actually a problem? You wouldn't share your password-recovery e-mail with anyone either?
I guess it's not the best thing to do (and not telling you to not share that mail), but a tremendous security hole? Are the login-tokens they use in the URL guessable? It not, I think that might be a little bit exaggerated...
- kathl_fritzsche 13y agoSession-tokens might be guessable, the one-click login urls include the user reference ID plus the date of the rollup mail.
- Piskvorrr 13y ago"Summary of some mostly uninteresting e-mails" doesn't quite feel as important or sensitive as "Password recovery e-mail". Very unintuitive, very surprising.