Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The key difference is that capturing a plaintext password means the user and attacker both share a password without the user realising, while capturing a reset link means that one of them will win and the other will observe their password reset has failed.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: