Hacker News new | past | comments | ask | show | jobs | submit login

That seems along the lines of "I can just turn off the ability to log in to prevent account hacking!" level of security thinking.



If your choices are "disable all logins" or "anybody can log into my bank account and make whatever transfers they want", the correct choice is the former. (Obviously I would prefer a third option, where the company actually fixed the login bug sometime during the 104-day lead-up, but that's not the point.)


For some accounts you do exactly that if you have to.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: