Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This does sound like a reasonable feature request to me: the "contact information" and "account recovery" use cases are different, and it's not obvious that an email listed for one should be automatically used for the other. They could have you choose for each email whether it's allowed to be used for account recovery.

As an analogous example, what if you did the "forgot my password" flow and they sent a recovery code over SMS to any listed phone number on your profile, sent a twitter DM to your listed twitter account, and sent postal mail to any postal address on your profile? (All at once, without waiting or confirmation.) That would expand the attack surface significantly, and it would be pretty easy to steal someone's account by stealing their postal mail. This case is similar: a secure email for account recovery and a less secure email for contact info, but Facebook forces you to use both for account recovery.

On the other hand, some people intentionally want multiple account recovery emails so they're less likely to lose access to their account. I imagine Facebook's hesitation with this feature is that it's hard to clearly communicate the distinction between the two use cases, and they want to bias toward simplicity.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: