Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, I gathered as much, but still, just a single URL to an email address to log me in? What about my 36 char password and my 2fa app?

Edit: I just found I didn't set up 2fa. I wonder, if I had, would they still do this? Then it would have just blatantly ignored my second factor...



They want control over the post content (in case it's deleted, edited, etc) and also track your interaction ASAP, so they link it instead of embed.

You will be asked to authenticate if you try to do anything.


Just checked, I am fully logged in in a clean ddg browser session, and can accept friend requests, etc. But I don't have 2fa enabled.


It may be that the link only worked once. Try again after logging out. Does it work?


Clicked it again, it says: The link you clicked may have stopped working or the page has been moved.

Can still log in as often as I want into clean browser sessions. Even when I log out, clean the session, tapping the url logs me in again.

And every time FB sends me an email: "Someone logged in from some location, was it you?"




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: