↳
In-reply-to
»
Hmm noting that
⤋ Read More
yarnd
password change function is insecure by design and should be fixed 🤔
@lyse@lyse.isobeef.org Well basically if you try to reset your password today, it assumes you are a) logged in and b) you are who you say you are. There is no verification of your old password, no identify verification. So if somehow someone managed to hijack your session or something…