ThisSpaceAvailable comments on My Heartbleed learning experience and alternative to poor quality Heartbleed instructions. - Less Wrong

14 Post author: aisarka 15 April 2014 08:15AM

You are viewing a comment permalink. View the original post to see all comments and the full post content.

Comments (31)

You are viewing a single comment's thread.

Comment author: ThisSpaceAvailable 16 April 2014 01:00:20AM 4 points [-]

This is pretty basic, but if you're compiling a list of instructions, it include that one should not reset passwords by following a link provided in an email, but rather one should type in the URL of the website manually and navigate to the password reset page.

And companies should stop sending password reset emails with links in them. That's just priming people for phishing.