Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They snatched defeat from the jaws of victory. All they needed to do was generate a little random data and email it to their clients.

eg. /reset?token=XXXXX

Only the recipient of the email can use it and it will let the person reset their password. It's so standard fare, I'm not sure why Sony needed to go this route.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: