3 ms·
Indeed, this is where common usage hasn't really caught up with best practice. It really is no better than showing the user their cleartext password. Ideally
by poutine 13y ago
Indeed, this is where common usage hasn't really caught up with best practice. It really is no better than showing the user their cleartext password.
Ideally you'd regenerate the key each time the user wants to show it or just use OAuth 2.0 (it's not as bad as everyone says it is).