14 ms·
Just tried the same and then entered my email again from another browser shortly after, as you suggested. The first sign in link expired but if your email clien
by shrew 7y ago
Just tried the same and then entered my email again from another browser shortly after, as you suggested. The first sign in link expired but if your email client displays threaded messages you could very easily click the second and think nothing of it.
That would allow the attacker in straight away, while also allowing your original browser in with a bit of faff. There's an active session list, but presumably most users wouldn't be looking at that.
Certainly made me more sceptical as I was otherwise quite interested!