Ask HN: Dealing with forgetful users without access to their email One of your users forgot her password and has no longer access to her email (because she signed up with a email from a company she no longer works at, or she has been hacked). You can't authenticate her, you only have some data about her that is easy to find out: Name, email, last 4 digits of credit card, etc. You have to make a judgement call so you can be social engineered. I am wondering how frequent are these edge cases like this, and how do you deal with them. |