Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

1
Security Flaw
Post Body

When I signed up using the app I signed up with email/password and then had to enter my phone number for two factor authentication. They never confirm your email address.

Fast forward to now and I get a new phone. Go to login and it asks for phone number for two factor authentication. I go through it and it says I need to enter email and password since my device wasn’t recognized.

Well turns out I misspelled my email. So someone out there has been getting my emails and since they can just use the email address to reset the password they can easily gain access to my account. You cannot reset the password via phone number and two factor authentication. You don’t even need that to login as far as I can tell.

I setup another account to test all those scenarios.

Anyway make sure your email is right because they won’t and then you risk someone taking over your account.

Author
Account Strength
70%
Account Age
2 years
Verified Email
Yes
Verified Flair
No
Total Karma
4,607
Link Karma
374
Comment Karma
4,233
Profile updated: 2 days ago
Posts updated: 5 months ago

Subreddit

Post Details

We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
11 months ago