Hacker News new | past | comments | ask | show | jobs | submit login

Don't most sites require that you enter your old password before you can change it?



Indeed, I guess this is a +1 against storing passwords plaintext (well, obtainable in any case) - as a person could change your password and take over the account completely


Not if you use the "reset" option. Which... you have their email account. So...


Heh. I wasn't even thinking about the "Forgot your password" feature. Better still.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: