Well spotted - I kind of mangled that explanation. The risk being mitigated is if somebody gets a dump of your old emails. Short-lived reset tokens don't help if they have full access to you email account.
Give it a try, it's free! We don't cover mobile specifically, but if you are building APIs, much of the advise is useful. And thinks like password management are useful for every developer to know. :-)
Author here! I put this together because I was bit frustrated with the quality of teaching resources for my development team. (And I find the OWASP wiki a bit of a mess.)
Not sure about the business model yet, though it's peaked some interest here and on /r/programming, so I figure there's an appetite for good training material.
https://www.reddit.com/r/InternetIsBeautiful/comments/4a4ol6...
The warmest feedback tended to come through PMs and email.