Note: The password in this image is no longer valid, don’t kill me

This is just used by their wiki, the side with the payment stuff uses a different system (and a separate login)

  • WatchfulConsole@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    8 days ago

    Not much different than a link to change your password that had those two random values added as a query parameter (which is what the link you get effectively does). Uncommon way to do it, but no real difference in the security model. Good to see they have a way to expire the password and force you to reset it if they ever had a compromise (since they note it has less than 1 day’s validity). Another upside is that by having already changed your password to this new random value, your account should also be locked until the password is changed. That one’s a mixed bag. Could be nice to know someone tried, could be frustrating if someone uses this to mildly DoS your account.