Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I would not use a TOTP but a stateless HMAC token in this case. I was only evoking TOTP because the original comment mentioned a 6-digit code (which is not a proper way to reset a password).


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: