Live data from Hacker News

Why don’t we do email verification in reverse?

blog.yossarian.net

181–190 of 329 posts

Re: Why don’t we do email verification in reverse?

#181
post #175

Earlier quoted context omitted.

Because services don't want to be spammed with fake accounts.

Could you be more precise about what you mean by "fake" accounts?

One person making multiple accounts to abuse the service. For example by spamming it.

Re: Why don’t we do email verification in reverse?

#182

Earlier quoted context omitted.

Why should I have to go through all that faff when I have a perfectly good password manager?

> Why should I have to go through all that faff when I have a perfectly good password manager? If you are not using dedicated special-purpose email addresses with specific services, you're already grossly mismanaging your online safety. Think about it for a second: how does your password manager help you if your email password gets leaked?

Thats a crazy level of risk assessment for an average user.

> how does your password manager help you if your email password gets leaked?

You still need my TOTP codes in my case at least, which conveniently are stored in my password manager. Is it perfectly secure? No, of course it's not, but frankly my risk profile isn't worrying about a targeted attack on me and my password manager, it's worrying about leaked shared credentials.

Side note, I also get a push notification on my phone whenever a new device logs on, so unless the attack is _extremely_ targeted, well timed and they know what they want, Its not a risk for me.

Re: Why don’t we do email verification in reverse?

#183
Author does not understand how many clueless people are there. Setting up an account is allreqdy a problem for a lot of people (both old and young people can be very non technical). This new system will often not work on a personal computer - those often dont have a configured mail client. All is done via web.

Also I can easily see this abused by tons of spamers, where every spam website will have a mailto: popup trying to catch inexperienced users - to reveal their emails.

Re: Why don’t we do email verification in reverse?

#186
post #160

I like that there's still options out there around authentication that I haven't seen before but this method is hostile towards folks without a dedicated email client. Personally I only ever login through web mail and have no client so `mailto` isn't a shortcut. I still think magic links are a good compromise. With a user / pass you still need to verify your email as a separate step. A magic link sends you an email a…

Magic Links mean that if there is any issue with any of the email servers in the chain (which there often are), my ability to log in to the website may be delayed by 10, 20, maybe even 30 minutes.

It’s unacceptable and everyone I know who uses magic link has eventually given up on them due to user unfamiliarity and a variety of issues such as this one.

Re: Why don’t we do email verification in reverse?

#187
post #37
post #29

Earlier quoted context omitted.

The standard login/sign up form is broken, though. People will just use the same password across websites or write it down. You can't win

Use a password manager. Problem solved.

No post body was provided.

Re: Why don’t we do email verification in reverse?

#188
post #181

Earlier quoted context omitted.

Could you be more precise about what you mean by "fake" accounts?

One person making multiple accounts to abuse the service. For example by spamming it.

Professional spammers probably would know how to set up fake email addresses.

Re: Why don’t we do email verification in reverse?

#190
I have a catchall. Sending mails is a bit annoying... I like not having to send a mail because I can easily avoid spam if someone misuses or sells my information because GDPR only hits small people and not the corps that deserve it. While yes, it may be slightly more annoying to create accounts, maybe that is a good thing. Because then you don't create an account at every possible site.
Post reply on HN