4 ms·
The standard email verification patterns rely on the user clicking a link. I am not sure how that would have helped here. Making users retype the email (instea
by zaidf 9y ago
The standard email verification patterns rely on the user clicking a link. I am not sure how that would have helped here.
Making users retype the email (instead of merely click on a link) might be better for exposing scams but requires more work on the user’s part.
- chatmasta 9y agoUltimately the bug relies on how believable the emails from Netflix are. If I got an email from Netflix asking me to update card details, I wouldn’t be surprised because maybe my card expired. But if I got an email asking to verify my new account, I would be very surprised. I didn’t sign up for a new Netflix account. If after that, I got an email to update my card details, I would be alarmed because of the recent unexpected signup email.
- zuminator 9y agoYes, I've received emails of the form, "You recently signed up on our website for Fooflix, please confirm by clicking here. If you did not recently sign up, please disregard this email. Anyway, now that this is a known problem, both Netflix and Gmail should take reasonable steps to mitigate.
- MrQuincle 9y agoMaybe some middle road: + Netflix can send an email about optionally(!) confirming a user's address. + Now, rather than disabling all features and slowing down on-boarding it is possible to update the communication towards unregistered users. + If an email has to be sent to an unconfirmed address, preceed it with a warning. If pietjepuk@gmail.com has been confirmed, but pietje.puk@gmail.com not, emails for the latter will have this warning automatically. + Remaining option: do you want to send regular safety requests to unconfirmed addresses as provider? Policy might differ. However, it is possible to use this email to tell the user about safety/security w.r.t. your system. I'd say yes.
- deleted 9y ago[deleted]