Originally Posted by Caveiradomar
This new system of security is very good
Now only the real account owner can change your personal data after confirming your code in email
congratulations
=)
The real account owner DOES NOT GET AN EMAIL.
The hijacker gets the e-mail and can use this to also change the second password. You do not need second password to change the registered e-mail and you can use the new e-mail to reset the second password.
Security just improved?
So anyone with your first PW can take all of the account and do what they want with it, using a Proxy Email. They can even spoof the IP so that you don't know you are buying stolen crew.
Way to go