Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you have a halfway competent security team they will never ever let this fly. You are begging your users to get phished.


Almost no one has a competent security team and if they do they don’t listen to them. Security is just compliance checkboxes and lists nowadays


A fully competent security team will, on the other hand, carry out a more comprehensive threat modelling exercise and make a pragmatic choice about whether this kind of auth flow is appropriate for your usecase.

The phishing risks for a bank account login are very different than those for a ‘returning player’ login to a casual gaming site for example.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: