The two security issues are user phishing and Netflix not performing canonicalization of email addresses. he signup process itself is not a security issue. The issue from the perspective of the user should be that the author clicked on a link in an html email, when he should have instead gone to Netflix.com. He clicked first and only then checked. Gmail even warned him of the phishing possibility, and he still clicke…
Where are you seeing this? I see no warning in the screen shot.
> Netflix not performing canonicalization of email addresses
AFAICT, Netflix CAN'T canonicalise the email address (unless they start making assumptions about specific providers) -- according to the RFCs, they can be different email addresses.