Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you request a password reset, sites typically send you an email containing a link with a secret in the URL. If the network is able to see your browser requesting that URL, it should be able to interrupt your connection and go change the password itself.


A good point, (although step 1 still saves you) the universal Achilles Heel strikes again!

I wish more sites would use a second factor for resets. This would prevent so many of these types of problems. Also, Windows knows that it's an untrusted network. Maybe warn about proxies if you have it (WPAD) turned on for Big Corp reasons?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: