>[...]
>LoginWithHN generates a unique one-time-use code that the user must then put into their profile within 5 minutes
I like the implementation, but shouldn't the code be something more explicit? Otherwise it might be easy to social engineer someone into putting in the code. Currently it's
>Put the token below in your HackerNews Profile ↗
>[random letters]
I think Keybase does something more explicit, with something like "my keybase verification code is xyz"