5 ms·
There are probably many valid answers to this, but my concern would be about bugs or other security failings allowing an attacker to alter one's registration de
by simmons 3y ago
There are probably many valid answers to this, but my concern would be about bugs or other security failings allowing an attacker to alter one's registration details (e.g. nameservers). This could be catastrophic, since everyone seems to base their security on email (e.g. password resets) these days, in true "pass the hard problem of identity and authentication on to someone else" fashion.
In other words, whoever controls the registration controls the nameservers, and whoever controls the nameservers controls the MX records, and whoever controls the MX records can reset passwords. (Ideally, we'd all be using MFA for every possible thing, but in practice that may not be possible for the hundreds of services one might be using.)