Live data from Hacker News

It's Time To Kill New User Confirmation Email Links

quist.co

1–10 of 50 posts

Re: It's Time To Kill New User Confirmation Email Links

#2
Perhaps I’ve missed some obvious reason why the industry still does this.

Because if you get a random email from some site you've never signed up for, there are two possible scenarios that you cannot distinguish between:

1) Somebody has maliciously signed you up to a legitimate site. 2) A malicious site is trying to get you to click a random link.

This proposal suffers from a common flaw, in which people assume they can change just one thing and have everything else in the world stay the same. Systems don't work like that.

Re: It's Time To Kill New User Confirmation Email Links

#3
This article misses a key point. If you want to confirm that the person who opted into your service is who they say they are. Otherwise, you're looking forward to abuse complaints from email recipients, and it only takes a few of those to suspend your Mailchimp (or whatever delivery service) account. You can also add non-compliance with spam, privacy and other laws to the list of fun things that could happen if you take this article's advice.

Re: It's Time To Kill New User Confirmation Email Links

#5
post #3

This article misses a key point. If you want to confirm that the person who opted into your service is who they say they are. Otherwise, you're looking forward to abuse complaints from email recipients, and it only takes a few of those to suspend your Mailchimp (or whatever delivery service) account. You can also add non-compliance with spam, privacy and other laws to the list of fun things that could happen if you t…

"In the edge case, where some unauthorized person has signed up using my email, then include some directions at the bottom of the email that instruct me how to deal with the abuse. And an extra benefit: If I have a good experience with your site reporting the abuse, I’ll be more interested to legitimately check out the site."

I'm not sure if I just don't understand what both of you are saying, but it seems he addressed this point towards the end of the post. I can't see how his solution ('click here if this isn't you') is any different than 'click here to confirm this is you' as far as potential abuse is concerned.

Re: It's Time To Kill New User Confirmation Email Links

#6
post #2

Perhaps I’ve missed some obvious reason why the industry still does this. Because if you get a random email from some site you've never signed up for, there are two possible scenarios that you cannot distinguish between: 1) Somebody has maliciously signed you up to a legitimate site. 2) A malicious site is trying to get you to click a random link. This proposal suffers from a common flaw, in which people assume they…

The author addresses the first issue in the paragraph preceding the one you quoted.

As it currently stands, most 'confirmation e-mails' I get also provide an 'if this isn't you' section. All the author is arguing is that we can do away with the confirmation part and keep the 'if this isn't you' part for those edge cases where a person's email address has been used by someone other than said person.

Re: It's Time To Kill New User Confirmation Email Links

#7
I'm more annoyed by having to pick a (unique) username. My name is too long and too common, all of the nice short versions are always already gone and why the hell am I so often not allowed to separate my first and (abbreviated) last name with a dot? Use my email address as the unique identifier and let me enter my first and last name or a nickname (which doesn't have to be unique), please.

Don't make me think. You should never ever have to show me the "This name is already in use." message. Your design shouldn't even need it. Not everyone has or would like to have an (as unique as possible) nickname on the web they would like to use.

(Unique) usernames are the one vestige of the old web I would like to get rid of post haste. Call me Michael. (I still positively remember signing up to Facebook because I didn't have to pick a username.)

Re: It's Time To Kill New User Confirmation Email Links

#9
post #5
post #3

This article misses a key point. If you want to confirm that the person who opted into your service is who they say they are. Otherwise, you're looking forward to abuse complaints from email recipients, and it only takes a few of those to suspend your Mailchimp (or whatever delivery service) account. You can also add non-compliance with spam, privacy and other laws to the list of fun things that could happen if you t…

"In the edge case, where some unauthorized person has signed up using my email, then include some directions at the bottom of the email that instruct me how to deal with the abuse. And an extra benefit: If I have a good experience with your site reporting the abuse, I’ll be more interested to legitimately check out the site." I'm not sure if I just don't understand what both of you are saying, but it seems he address…

Because if you're the innocent target of a malicious sign-up then you shouldn't have to take any further action - particularly action that could expose you to further harm, such as clicking on a link randomly emailed to you from some site you've never heard of - to avoid having your email address associated with the account.

Edit: You also shouldn't have to be watching your email like a hawk 24/7 just in case somebody signs you up for something, so that you can stop them from impersonating you before they do any damage.

In short, it's the difference between opt-in and opt-out. Identity theft should almost never be opt-out.

Re: It's Time To Kill New User Confirmation Email Links

#10
post #5
post #3

This article misses a key point. If you want to confirm that the person who opted into your service is who they say they are. Otherwise, you're looking forward to abuse complaints from email recipients, and it only takes a few of those to suspend your Mailchimp (or whatever delivery service) account. You can also add non-compliance with spam, privacy and other laws to the list of fun things that could happen if you t…

"In the edge case, where some unauthorized person has signed up using my email, then include some directions at the bottom of the email that instruct me how to deal with the abuse. And an extra benefit: If I have a good experience with your site reporting the abuse, I’ll be more interested to legitimately check out the site." I'm not sure if I just don't understand what both of you are saying, but it seems he address…

Such a "not me" link only prevents abuse if the person receiving that email checks their email the instant it's sent and clicks the "not me" link instantly as well. Otherwise, someone could sign up for a site using a random person's email address and then do something malicious depending on the site/service... send emails/messages, post nasty forum messages, etc.

Granted, not all sites/services can be used for such maliciousness, but in those cases that the site can be used maliciously, a "not me" link is a corrective measure and not preventative measure.

Edit: zb put it more eloquently than I did.

Post reply on HN