It's Time To Kill New User Confirmation Email Links
1–10 of 50 posts
Re: It's Time To Kill New User Confirmation Email Links
#2Because if you get a random email from some site you've never signed up for, there are two possible scenarios that you cannot distinguish between:
1) Somebody has maliciously signed you up to a legitimate site. 2) A malicious site is trying to get you to click a random link.
This proposal suffers from a common flaw, in which people assume they can change just one thing and have everything else in the world stay the same. Systems don't work like that.
Re: It's Time To Kill New User Confirmation Email Links
#3Re: It's Time To Kill New User Confirmation Email Links
#4Try it :) The email is used to set up your password, but you are able to use the app the first time without it! That way you will likely visit the app again when you check your email.
Re: It's Time To Kill New User Confirmation Email Links
#5This article misses a key point. If you want to confirm that the person who opted into your service is who they say they are. Otherwise, you're looking forward to abuse complaints from email recipients, and it only takes a few of those to suspend your Mailchimp (or whatever delivery service) account. You can also add non-compliance with spam, privacy and other laws to the list of fun things that could happen if you t…
I'm not sure if I just don't understand what both of you are saying, but it seems he addressed this point towards the end of the post. I can't see how his solution ('click here if this isn't you') is any different than 'click here to confirm this is you' as far as potential abuse is concerned.
Re: It's Time To Kill New User Confirmation Email Links
#6Perhaps I’ve missed some obvious reason why the industry still does this. Because if you get a random email from some site you've never signed up for, there are two possible scenarios that you cannot distinguish between: 1) Somebody has maliciously signed you up to a legitimate site. 2) A malicious site is trying to get you to click a random link. This proposal suffers from a common flaw, in which people assume they…
As it currently stands, most 'confirmation e-mails' I get also provide an 'if this isn't you' section. All the author is arguing is that we can do away with the confirmation part and keep the 'if this isn't you' part for those edge cases where a person's email address has been used by someone other than said person.
Re: It's Time To Kill New User Confirmation Email Links
#7Don't make me think. You should never ever have to show me the "This name is already in use." message. Your design shouldn't even need it. Not everyone has or would like to have an (as unique as possible) nickname on the web they would like to use.
(Unique) usernames are the one vestige of the old web I would like to get rid of post haste. Call me Michael. (I still positively remember signing up to Facebook because I didn't have to pick a username.)
Re: It's Time To Kill New User Confirmation Email Links
#8Because it's really that hard to Ctrl+click a link in an email, archive it, and move on to the next email?
Re: It's Time To Kill New User Confirmation Email Links
#9This article misses a key point. If you want to confirm that the person who opted into your service is who they say they are. Otherwise, you're looking forward to abuse complaints from email recipients, and it only takes a few of those to suspend your Mailchimp (or whatever delivery service) account. You can also add non-compliance with spam, privacy and other laws to the list of fun things that could happen if you t…
"In the edge case, where some unauthorized person has signed up using my email, then include some directions at the bottom of the email that instruct me how to deal with the abuse. And an extra benefit: If I have a good experience with your site reporting the abuse, I’ll be more interested to legitimately check out the site." I'm not sure if I just don't understand what both of you are saying, but it seems he address…
Edit: You also shouldn't have to be watching your email like a hawk 24/7 just in case somebody signs you up for something, so that you can stop them from impersonating you before they do any damage.
In short, it's the difference between opt-in and opt-out. Identity theft should almost never be opt-out.
Re: It's Time To Kill New User Confirmation Email Links
#10This article misses a key point. If you want to confirm that the person who opted into your service is who they say they are. Otherwise, you're looking forward to abuse complaints from email recipients, and it only takes a few of those to suspend your Mailchimp (or whatever delivery service) account. You can also add non-compliance with spam, privacy and other laws to the list of fun things that could happen if you t…
"In the edge case, where some unauthorized person has signed up using my email, then include some directions at the bottom of the email that instruct me how to deal with the abuse. And an extra benefit: If I have a good experience with your site reporting the abuse, I’ll be more interested to legitimately check out the site." I'm not sure if I just don't understand what both of you are saying, but it seems he address…
Granted, not all sites/services can be used for such maliciousness, but in those cases that the site can be used maliciously, a "not me" link is a corrective measure and not preventative measure.
Edit: zb put it more eloquently than I did.