Post
Topic
Board Meta
Re: 'Password reset via email' option used to hack the account?
by
F8N00
on 10/03/2018, 16:39:12 UTC
The code is 10 random characters from an alphabet of 62 characters; you're never brute-forcing that over a network. You'd bring down the forum before you got to even 10000 attempts per second. Most likely the email was intercepted at his end somehow.

Why don't we have confirmation email before the password can be changed?