Live data from Hacker News

It's Time To Kill New User Confirmation Email Links

quist.co

21–30 of 50 posts

Re: It's Time To Kill New User Confirmation Email Links

#21
post #2

Perhaps I’ve missed some obvious reason why the industry still does this. Because if you get a random email from some site you've never signed up for, there are two possible scenarios that you cannot distinguish between: 1) Somebody has maliciously signed you up to a legitimate site. 2) A malicious site is trying to get you to click a random link. This proposal suffers from a common flaw, in which people assume they…

Compounding this problem, conventional security wisdom is that you should never acknowledge unsolicited email, because the spammer might be using a fake unsubscribe link to confirm your email address is real. So a system that requires manual unsubscription this way will actually punish accidentally subscribed users for following good protocol.

Furthermore, if the "confirmation" email winds up in a spam filter and the user never sees it, subsequent emails will still go out and probably be auto-marked as spam.

Re: It's Time To Kill New User Confirmation Email Links

#22
post #5
post #3

This article misses a key point. If you want to confirm that the person who opted into your service is who they say they are. Otherwise, you're looking forward to abuse complaints from email recipients, and it only takes a few of those to suspend your Mailchimp (or whatever delivery service) account. You can also add non-compliance with spam, privacy and other laws to the list of fun things that could happen if you t…

"In the edge case, where some unauthorized person has signed up using my email, then include some directions at the bottom of the email that instruct me how to deal with the abuse. And an extra benefit: If I have a good experience with your site reporting the abuse, I’ll be more interested to legitimately check out the site." I'm not sure if I just don't understand what both of you are saying, but it seems he address…

Opt in vs opt out. It makes a difference under the law.

Re: It's Time To Kill New User Confirmation Email Links

#23
Strongly disagree. All of the identity issues aside, ensuring deliverability is another key issue. Some email providers can be very aggressive when it comes to marking emails from new services as spam. Getting a user to pick a confirmation email out of their spam folder and click "Not Spam" is the most important action that user can do as part of the signup process, otherwise you will never reach that person's inbox again.

Re: It's Time To Kill New User Confirmation Email Links

#24
post #18

"When I’m checking my email, the last thing I want to do is context switch back to the app." Umm you are signing up for a service, when you click the "register" button, you are usually presented with a message "check your email for a confirmation link" so you go do that. Where is context switching here? Most of the users don't signup for something and then forget about it until they, by accident, stumble upon the ema…

I agree. When I sign up for a service the confirmation email is generally already in my inbox by the time I switch tabs to gmail. Then the confirmation link takes me back to the site and logs me in, no hard work involved.

Also, I've never registered for a service and decided not to immediately check my email to activate my account when I'm prompted to. I can't recall a single time when I've come across a confirmation link while casually checking my email.

Re: It's Time To Kill New User Confirmation Email Links

#25
post #7

I'm more annoyed by having to pick a (unique) username. My name is too long and too common, all of the nice short versions are always already gone and why the hell am I so often not allowed to separate my first and (abbreviated) last name with a dot? Use my email address as the unique identifier and let me enter my first and last name or a nickname (which doesn't have to be unique), please. Don't make me think. You s…

the easy solution to this is your email as a username/login. that way it's guaranteed unique. the only problem is multiple john smiths confusing people

Email addresses may be unique at one point of time, but assuming that they are unique identifiers for people is problematic because they can legitimately change hands. For instance, my work email address is @. I'm not the first at - the other one left before I joined, but two months after I took over the email address I'm still clearing up the accounts with services that made an identity assumption over email addresses.

Re: It's Time To Kill New User Confirmation Email Links

#27

Earlier quoted context omitted.

the easy solution to this is your email as a username/login. that way it's guaranteed unique. the only problem is multiple john smiths confusing people

Email addresses may be unique at one point of time, but assuming that they are unique identifiers for people is problematic because they can legitimately change hands. For instance, my work email address is @ . I'm not the first at - the other one left before I joined, but two months after I took over the email address I'm still clearing up the accounts with services that made an identity assumption over email addres…

Isn't there a problem if you sign-up to services with your "temporary" work email? Get a gmail account and sit on it, what's wrong with that?

Re: It's Time To Kill New User Confirmation Email Links

#28
post #7

I'm more annoyed by having to pick a (unique) username. My name is too long and too common, all of the nice short versions are always already gone and why the hell am I so often not allowed to separate my first and (abbreviated) last name with a dot? Use my email address as the unique identifier and let me enter my first and last name or a nickname (which doesn't have to be unique), please. Don't make me think. You s…

the easy solution to this is your email as a username/login. that way it's guaranteed unique. the only problem is multiple john smiths confusing people

You can use Gravatar to show different pictures for every John Smith.

Re: It's Time To Kill New User Confirmation Email Links

#29
post #23

Strongly disagree. All of the identity issues aside, ensuring deliverability is another key issue. Some email providers can be very aggressive when it comes to marking emails from new services as spam. Getting a user to pick a confirmation email out of their spam folder and click "Not Spam" is the most important action that user can do as part of the signup process, otherwise you will never reach that person's inbox…

Yes, and besides aggressive spam filtering, it's just a good way to confirm a usable communication channel before you need to use that channel.

Re: It's Time To Kill New User Confirmation Email Links

#30
I just want to attach an anecdote here and explain why I prefer confirmation emails.

One day, somewhere in the last couple months, I checked my email box and saw a message from some craft site. It was informing me that my paid subscription was activated and that I was entitled to X, Y, and Z services. I ignored it. I received another related email the next day. I ignored that, too. When I received a third with another advertisement, I realized this was legitimate and that someone had accidentally used my email address! My inclination was to find someone in control of the site and let them know the mistake so that the original person could see their offers and track their subscription. I headed to the website and noticed the login form on the first page.

Curiosity struck me. Was this one of those sites that people make fun of online with bad security? I clicked the link saying I forgot my password. They asked not for my username but for my email address. So I entered that. Next thing I know, my Inbox has an email from the craft site with the registered user's plaintext password!

Uh oh. Is this for real? What if I was a malicious user? I had to see how bad this situation really was. I logged into the user's account. I was able to find their home address and phone number, but thankfully (dear Lord, thankfully), the website made no mention of credit card numbers. I did not look to see if I could order more service; at that point and in my shock over the situation, I felt I was deep into some weird grey area and was way past my welcome. I logged out, found an online contact form, and explained the situation as well as how they could improve their system to avoid harm to their users.

The security mistakes in this situation were compounded.

(1) Email alerts went to the wrong person. If you verify the email, the right people get the messages. If you do not verify the email, the wrong person can mark your site as spam or take advantage of the situation.

(2) The site stored plaintext passwords. This was a craft site... By the name of the victim and other factors, I realized that this was some old lady who has faith in the trustworthiness of the Internet and probably, like most typical people, uses the same password for multiple sites. And this site happily handed it over to a stranger. That, my friends, is scary.

People make honest mistakes. If the email address is important for account management, send a verification email. And give the user an opportunity to fix the problem in the event that that verification fails in some way.

Post reply on HN