Hacker News new | past | comments | ask | show | jobs | submit login

What is that going to do, the outcome is the attacker still has the password hash and the linked email address?



So how do they log in without a username & password ?


To your site, they probably don't. But they'll take the email and password and use it elsewhere. You'll have still exposed your customers.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: