• laxsill@infosec.pub
    ·
    11 months ago

    Their policy should just be to reset the password immediately and have the user set a new one. This is one hell of a risk.

    • XTornado@lemmy.ml
      ·
      edit-2
      11 months ago

      That would imply they have to test that the credentials are correct though.

      Otherwise I can just put somebody's user and put some fake password and they would reset it and disconnect the account of that user and annoy him.