Live data from Hacker News

It's Time To Kill New User Confirmation Email Links

quist.co

31–40 of 50 posts

Re: It's Time To Kill New User Confirmation Email Links

#32
post #7

I'm more annoyed by having to pick a (unique) username. My name is too long and too common, all of the nice short versions are always already gone and why the hell am I so often not allowed to separate my first and (abbreviated) last name with a dot? Use my email address as the unique identifier and let me enter my first and last name or a nickname (which doesn't have to be unique), please. Don't make me think. You s…

Are you suggesting sites should allow duplicate usernames and allow you to log in with that username and one of the correct passwords associated with it?

Re: It's Time To Kill New User Confirmation Email Links

#34
post #7

I'm more annoyed by having to pick a (unique) username. My name is too long and too common, all of the nice short versions are always already gone and why the hell am I so often not allowed to separate my first and (abbreviated) last name with a dot? Use my email address as the unique identifier and let me enter my first and last name or a nickname (which doesn't have to be unique), please. Don't make me think. You s…

Are you suggesting sites should allow duplicate usernames and allow you to log in with that username and one of the correct passwords associated with it?

No he's suggesting to allow people to log in with their email and let them pick whatever username/nickname they want. Think Stackoverflow for example.

Re: It's Time To Kill New User Confirmation Email Links

#36
post #9
post #5

Earlier quoted context omitted.

"In the edge case, where some unauthorized person has signed up using my email, then include some directions at the bottom of the email that instruct me how to deal with the abuse. And an extra benefit: If I have a good experience with your site reporting the abuse, I’ll be more interested to legitimately check out the site." I'm not sure if I just don't understand what both of you are saying, but it seems he address…

Because if you're the innocent target of a malicious sign-up then you shouldn't have to take any further action - particularly action that could expose you to further harm, such as clicking on a link randomly emailed to you from some site you've never heard of - to avoid having your email address associated with the account. Edit: You also shouldn't have to be watching your email like a hawk 24/7 just in case somebod…

More than that - a number of services (for example B2B SaaS) depend on knowing the email identity of their user. Are you John Jones ? Of course you are, you signed up with that email address and the system accepted you.

If a system like, say, Woobius, doesn't confirm emails, people will abuse this lack of feature.

Re: It's Time To Kill New User Confirmation Email Links

#37

Earlier quoted context omitted.

the easy solution to this is your email as a username/login. that way it's guaranteed unique. the only problem is multiple john smiths confusing people

Email addresses may be unique at one point of time, but assuming that they are unique identifiers for people is problematic because they can legitimately change hands. For instance, my work email address is @ . I'm not the first at - the other one left before I joined, but two months after I took over the email address I'm still clearing up the accounts with services that made an identity assumption over email addres…

Similarly, I'm still getting e-mails for [username]@[isp] because the username I chose has been used by several prior users, and just happened to be free at the moment I signed up.

Re: It's Time To Kill New User Confirmation Email Links

#38
Apple id seems to implement the proposed solution. They send a verification email but you don't actually have to click the link, you can just ignore it and your account works.

This can turn out bad though. I thought I had an apple-id when buying something on the apple site recently. But my standard passwords didn't work so I reset the password (via an email sent to me personal email address from the password reset sequence). When I logged in I found that my email address was actually registered to someone else, and I had their name, full address, phone number and credit card number but with the first 12 digits X'd out.

The person has a similar name to mine, and my email address is my initials and last name, so I believe they just made a typo in the email address when they signed up. But it seems pretty bad that you can do that without verification when doing so can give someone your personal information.

A motivated scammer could register a bunch of typoed email addresses and try resetting apple-id passwords. Then you have a 1 in 333 chance of buying stuff with their credit card because you have to guess the security code (I'm guessing you get 3 chances but you might get more).

Re: It's Time To Kill New User Confirmation Email Links

#39

So the overwhelming attitude here is that the advice in the link is bad, so why does it still have 32 points and waste my time by being on the front page? Please down vote articles like this.

It probably has that many points because there are some interesting discussions going on in the comments.

Re: It's Time To Kill New User Confirmation Email Links

#40
post #7

I'm more annoyed by having to pick a (unique) username. My name is too long and too common, all of the nice short versions are always already gone and why the hell am I so often not allowed to separate my first and (abbreviated) last name with a dot? Use my email address as the unique identifier and let me enter my first and last name or a nickname (which doesn't have to be unique), please. Don't make me think. You s…

If you want vanity urls then you still have to have unique username.
Post reply on HN