Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I include an "Instant Login" link in each mail so the users don't need to remember their password. It contains a unique time-sensitive token to identify the user and instantly sign them in (much like a password reset). I learned this technique from OKCupid, so no idea why they still had plaintext passwords.


It turns out Cupid Media is unrelated to OkCupid.


Maybe simply emailing the password still has a higher conversion rate than the one time link, for example if the user does not see or understand the link or perhaps they want to login later when their email is not open.

It can be difficult to argue for security in cases where even small % of short term revenue might be affected.


I hope you educated your users not to forward any of that mail.


After how much time will the token expire?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: