logoalt Hacker News

k12sosseyesterday at 10:40 PM1 replyview on HN

As a [email protected] holder, unfiltered spam is less commonplace than a) websites adding me to distribution/mailing lists without verifying I was the person to type it in, b) people who either accidentally transform their address into mine, or forget part of their address.

These are from all parts of the globe. I have access to bank accounts in South America, Disney employee music royalty earnings tax disclosures and forms, European subscribers online platforms, AWS account recovery options, veterinarian records in Studio City, private school/PTA leadership website access in Mountain View.

I stopped trying to return unopened mail, nobody cared.

I don't do anything with any of this because I'm not a giant fool, but people, have your users verify their email addresses before you trust them.


Replies

nabbedtoday at 12:12 AM

Ha! Me too. I have [email protected], which means [email protected] (without the dot) also maps to my email account. (first and last are placeholders for my actual name, of course).

I get lots of stuff intended for other people (including a mildly famous person with my name whose actual email address is [email protected]).

A few years ago, someone set up a shopify account with my email address. Overnight while I slept, the shopify account was created, did some bad stuff, and got suspended for fraudulent activity. The whole story was told through the series of emails coming in over a couple of hours. Shopify did not required the fraudster to confirm the email address to activate the account.

When I asked shopify to unlink my email address from this fraudster account, they instructed me to click on the "forgot my password" link on their login page, click on the "change password" link in the resulting email, and then login and remove my email from the account. This was my only option, they claimed. Obviously, I was never going to connect my IP address with some fraudster's Shopify account, so I just left it as-is.

I guess services feel it adds too much "friction" to force a user to verify the specified email account before allowing them to use the service.