4 ms·
The funny thing is that CAN-SPAM mandates 1-click opt-out, and requiring login to unsubscribe is specifically prohibited.[1] So most websites already have code
by randomwalker 15y ago
The funny thing is that CAN-SPAM mandates 1-click opt-out, and requiring login to unsubscribe is specifically prohibited.[1] So most websites already have code to include and verify auth tokens in emailed links, which they utilize when they are mandated to.
But somehow they haven't figured out that it is in their own interest to do so the rest of the time.
[1] http://blogs.boomerang.com/blog/2009/06/16/can-spam-2008-unsubscribe-provisions/ http://blogs.boomerang.com/blog/2009/06/16/can-spam-2008-uns...
- thirsteh 15y agoYou can use such tokens to disable email notifications, and still not provide complete access to the account, though.
- danenania 15y agoThis seems like a good compromise. Allow immediate access for convenience in some cases, but restrict that access to a specific task until login.
- thirsteh 15y agoYes, but the scope of access would have to be severely limited, to the point where's there's no real sense in doing it, e.g. you'd have to prompt for settings change, but also probably read/write access to private messages, wall, etc... It'd be a lot of work with little return (the more return, the less security).
- danenania 15y agoYeah, good points.
- zaidf 15y agoAFAIK CAN-Spam only applies for unsolicited emails, so a newsletter from a service you opted into does not need to abide by it. May be I'm mistaken.
- pbreit 15y ago> CAN-SPAM mandates 1-click opt-out Actually it requires one-click or two-click. And not for transactional emails.