DKIM et. al. security concerns aside, I don't think a mailto link will be easier to use because the web server doesn't control the user's configured handler for mailto links and there's a lot of ways for that link to go unhappy.
Why don’t we do email verification in reverse?
191–200 of 329 posts
Re: Why don’t we do email verification in reverse?
#192I've had family members fall prey to phishing scams. I would be concerned if legitimate sites trained their users to send odd content to odd addresses as part of normal net usage. How can an ordinary person understand the difference between sending a token to real.com and sending a threat to another user on behalf of fake.com?
Re: Why don’t we do email verification in reverse?
#193Re: Why don’t we do email verification in reverse?
#194Re: Why don’t we do email verification in reverse?
#195No, because email forwarding is a thing and many people use it
Re: Why don’t we do email verification in reverse?
#196Earlier quoted context omitted.
I do and tell people to do the same. Unfortunately we can't force people to actually do it.
Unpopular take: users should be free to use bad and insecure passwords for services they don't care about.
Re: Why don’t we do email verification in reverse?
#197Besides the security and usability problems others mentioned, I also highly doubt it will improve confirmation conversions. One thing that helped us improve confirmations -- we A/B tested it and confirmation rates increased ~8%: send a 4-digit confirmation code rather than just a link. It's easier and more familiar on mobile, especially if you see the code on the push notification, so don't even need to open the emai…
While the 4 digit code is easy enough to read on their phone in a notification and then type into the other device.
Re: Why don’t we do email verification in reverse?
#198Earlier quoted context omitted.
> - not everybody has SPF or DKIM, and definitely not everybody has DKIM. A correctly configured mailserver should reject your email (or mark it as spam) if you don't use both DKIM and SPF. It's safe to assume 99.999% of users use both.
I have plenty of emails in my inbox that don't use both. I think you're off by several orders of magnitude.
Around between four and four and a half orders of magnitude for the Fortune 100, with five orders being the maximum possible wrongness.
Re: Why don’t we do email verification in reverse?
#199I say: let them experiment. Let this guy implement his clever scheme and see how spam bots population increases several folds and conversion drops 10-15%. If he knows what conversion is and have a metrics for it. And knows what metrics are, also. And if spammers are interested at all in his product. Or whatever.
Also let the legion of newbies and dilettantes vote articles like this to the moon and higher. Let it sit in top 1 HN for weeks. At the end, isn't it a creativity and smartness we should praise and encourage? This is Hacker News, home of brightest startup ideas.
After all, it is good for us, old and inert creeps. Ones who knows what metrics are, how to collect, store and analyse them, how to implement A/B test, and what "statistical significance" means. We still will have several open offers even when all the code would be written by GitHub Copilot, all the texts by GPT3 and all the art by DALL-E.
Forget about retirement, folks, there are interesting times ahead.
Re: Why don’t we do email verification in reverse?
#200Earlier quoted context omitted.
> Why should I have to go through all that faff when I have a perfectly good password manager? If you are not using dedicated special-purpose email addresses with specific services, you're already grossly mismanaging your online safety. Think about it for a second: how does your password manager help you if your email password gets leaked?
Thats a crazy level of risk assessment for an average user. > how does your password manager help you if your email password gets leaked? You still need my TOTP codes in my case at least, which conveniently are stored in my password manager. Is it perfectly secure? No, of course it's not, but frankly my risk profile isn't worrying about a targeted attack on me and my password manager, it's worrying about leaked share…
It really isn't. Think about it for a second: how hard is it to spot phishing attempts when they are sent to an email address you know for a fact you're not using with a service?
And how vulnerable are you to phishing if your special-purpose email address that you only use for one specific purpose receives zero spam?
To claim that the most basic and easy internet security precautions are at a "crazy level", first you need to somehow believe that no one is targeted by these schemes. But somehow there's a whole international industry that thrives on stuff like Western Union transfers. Why is that?