It isn't clear to me that the code is actually generated on the client. Much more likely is that it was created on the server and simply sent to the client, possibly because the account creation server has no ability to send emails. As a stateless protocol, HTTP is an absolutely terrible thing to be using for these sorts of transactional processes, especially if we're looking for security. It's a real shame that the web has become the lowest common denominator for most people on the Internet. a73aa159d271867d61bb9f555b757e8713b71d62fcc6581e2352661f8a96df4e