• 5 Posts
  • 80 Comments
Joined 1 year ago
cake
Cake day: June 20th, 2023

help-circle








  • Not really the only reason. It would be better to just return “token invalid”.

    It could occur by someone messing with the URL from the reset password email, like accidently adding an extra character before pressing enter

    Or a poor email client that wraps the URL and doesn’t send the complete one when clicked.

    Or someone attempting to find a weakness in the reset password system and sending junk as the token.









  • Okay, I understand so far.

    What I am struggling with is the limitations of duristriction.

    So the EU finds the Australian company in breach of their rules. They send a notice of intent to pursue damages to the Australian company. And they tell the EU to kick rocks.

    Surely laws made up in one country don’t apply in all. The internet makes this a muddy area, as it’s fully connected and nothing is stopping Joe in Netherlands from signing up to a service hosted in Vietnam. The Vietnam company can just ignore GDPR, ignore requests, ignore fines.