Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you're logged into your e-mail, then someone can go to Facebook, and start password recovery, and then go to your e-mail and click the recovery link. If you're not logged in, then the OpenID authentication will require you to enter your e-mail. This isn't a weakness, just a convenience.


How is that not a weakness if anyone who has access to your computer can set an arbitrary password on your facebook account? (given you are logged into your gmail). I think it would be a nice feature if facebook would use that information to force a relogin




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: