Live data from Hacker News

It's Time To Kill New User Confirmation Email Links

quist.co

11–20 of 50 posts

Re: It's Time To Kill New User Confirmation Email Links

#11
post #6
post #2

Perhaps I’ve missed some obvious reason why the industry still does this. Because if you get a random email from some site you've never signed up for, there are two possible scenarios that you cannot distinguish between: 1) Somebody has maliciously signed you up to a legitimate site. 2) A malicious site is trying to get you to click a random link. This proposal suffers from a common flaw, in which people assume they…

The author addresses the first issue in the paragraph preceding the one you quoted. As it currently stands, most 'confirmation e-mails' I get also provide an 'if this isn't you' section. All the author is arguing is that we can do away with the confirmation part and keep the 'if this isn't you' part for those edge cases where a person's email address has been used by someone other than said person.

But the "if this isn't you" part could be a scam. It would make you click on a link in an email you did not request, which is a bad idea.

Re: It's Time To Kill New User Confirmation Email Links

#12
post #6
post #2

Perhaps I’ve missed some obvious reason why the industry still does this. Because if you get a random email from some site you've never signed up for, there are two possible scenarios that you cannot distinguish between: 1) Somebody has maliciously signed you up to a legitimate site. 2) A malicious site is trying to get you to click a random link. This proposal suffers from a common flaw, in which people assume they…

The author addresses the first issue in the paragraph preceding the one you quoted. As it currently stands, most 'confirmation e-mails' I get also provide an 'if this isn't you' section. All the author is arguing is that we can do away with the confirmation part and keep the 'if this isn't you' part for those edge cases where a person's email address has been used by someone other than said person.

Usually the 'if this isn't you' section says "don't click the link above" or "do nothing and you won't hear from us again".

Re: It's Time To Kill New User Confirmation Email Links

#13
The article assumes that people are happy to click on a link within an email from an unrecognised source, in order to cancel a fake member account. This rings all sorts of alarm bells, I would never do that.

If I got an email like that, I would click the spam button and the server would probably face regular spam blacklist issues from big providers.

Re: It's Time To Kill New User Confirmation Email Links

#15
post #4

We have a better way of signing up on qbix.com Try it :) The email is used to set up your password, but you are able to use the app the first time without it! That way you will likely visit the app again when you check your email.

Doesn't that make it even easier for malicious users/bots to cause problems? How does qbix.com strategise against that?

Re: It's Time To Kill New User Confirmation Email Links

#17
post #13

The article assumes that people are happy to click on a link within an email from an unrecognised source, in order to cancel a fake member account. This rings all sorts of alarm bells, I would never do that. If I got an email like that, I would click the spam button and the server would probably face regular spam blacklist issues from big providers.

This. Silence is not consent, and if you start mailing me regularly because I did not browse to some URL telling you not to, you are a spammer and I will treat you as such.

Re: It's Time To Kill New User Confirmation Email Links

#18
"When I’m checking my email, the last thing I want to do is context switch back to the app."

Umm you are signing up for a service, when you click the "register" button, you are usually presented with a message "check your email for a confirmation link" so you go do that. Where is context switching here?

Most of the users don't signup for something and then forget about it until they, by accident, stumble upon the email when they check their inbox the next time. Or am I wrong?

Re: It's Time To Kill New User Confirmation Email Links

#20
post #7

I'm more annoyed by having to pick a (unique) username. My name is too long and too common, all of the nice short versions are always already gone and why the hell am I so often not allowed to separate my first and (abbreviated) last name with a dot? Use my email address as the unique identifier and let me enter my first and last name or a nickname (which doesn't have to be unique), please. Don't make me think. You s…

the easy solution to this is your email as a username/login. that way it's guaranteed unique. the only problem is multiple john smiths confusing people
Post reply on HN