Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you're emailing users' passwords you've got bigger problems than a bit of trailing white space.


Lots of systems email users an initial password which must be changed at first login. It's not the world's most elegant solution, but it's also not terrible and basically does an implicit email verification. I'm not sure that it's any worse than sending a URL with an embedded token that takes the user to a password-change page.


>but it's also not terrible

It's terrible. Really.

https://news.ycombinator.com/item?id=7943365


Like everything in IT security, it's about your use case, threat matrix, and risk assessment.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: