It's Time To Kill New User Confirmation Email Links
quist.co
quist.co
Because if you get a random email from some site you've never signed up for, there are two possible scenarios that you cannot distinguish between:
1) Somebody has maliciously signed you up to a legitimate site. 2) A malicious site is trying to get you to click a random link.
This proposal suffers from a common flaw, in which people assume they can change just one thing and have everything else in the world stay the same. Systems don't work like that.
As it currently stands, most 'confirmation e-mails' I get also provide an 'if this isn't you' section. All the author is arguing is that we can do away with the confirmation part and keep the 'if this isn't you' part for those edge cases where a person's email address has been used by someone other than said person.
Furthermore, if the "confirmation" email winds up in a spam filter and the user never sees it, subsequent emails will still go out and probably be auto-marked as spam.
One day, somewhere in the last couple months, I checked my email box and saw a message from some craft site. It was informing me that my paid subscription was activated and that I was entitled to X, Y, and Z services. I ignored it. I received another related email the next day. I ignored that, too. When I received a third with another advertisement, I realized this was legitimate and that someone had accidentally used my email address! My inclination was to find someone in control of the site and let them know the mistake so that the original person could see their offers and track their subscription. I headed to the website and noticed the login form on the first page.
Curiosity struck me. Was this one of those sites that people make fun of online with bad security? I clicked the link saying I forgot my password. They asked not for my username but for my email address. So I entered that. Next thing I know, my Inbox has an email from the craft site with the registered user's plaintext password!
Uh oh. Is this for real? What if I was a malicious user? I had to see how bad this situation really was. I logged into the user's account. I was able to find their home address and phone number, but thankfully (dear Lord, thankfully), the website made no mention of credit card numbers. I did not look to see if I could order more service; at that point and in my shock over the situation, I felt I was deep into some weird grey area and was way past my welcome. I logged out, found an online contact form, and explained the situation as well as how they could improve their system to avoid harm to their users.
The security mistakes in this situation were compounded.
(1) Email alerts went to the wrong person. If you verify the email, the right people get the messages. If you do not verify the email, the wrong person can mark your site as spam or take advantage of the situation.
(2) The site stored plaintext passwords. This was a craft site... By the name of the victim and other factors, I realized that this was some old lady who has faith in the trustworthiness of the Internet and probably, like most typical people, uses the same password for multiple sites. And this site happily handed it over to a stranger. That, my friends, is scary.
People make honest mistakes. If the email address is important for account management, send a verification email. And give the user an opportunity to fix the problem in the event that that verification fails in some way.
I'm not sure if I just don't understand what both of you are saying, but it seems he addressed this point towards the end of the post. I can't see how his solution ('click here if this isn't you') is any different than 'click here to confirm this is you' as far as potential abuse is concerned.
Edit: You also shouldn't have to be watching your email like a hawk 24/7 just in case somebody signs you up for something, so that you can stop them from impersonating you before they do any damage.
In short, it's the difference between opt-in and opt-out. Identity theft should almost never be opt-out.
If a system like, say, Woobius, doesn't confirm emails, people will abuse this lack of feature.
Granted, not all sites/services can be used for such maliciousness, but in those cases that the site can be used maliciously, a "not me" link is a corrective measure and not preventative measure.
Edit: zb put it more eloquently than I did.
If I got an email like that, I would click the spam button and the server would probably face regular spam blacklist issues from big providers.
Don't make me think. You should never ever have to show me the "This name is already in use." message. Your design shouldn't even need it. Not everyone has or would like to have an (as unique as possible) nickname on the web they would like to use.
(Unique) usernames are the one vestige of the old web I would like to get rid of post haste. Call me Michael. (I still positively remember signing up to Facebook because I didn't have to pick a username.)
Umm you are signing up for a service, when you click the "register" button, you are usually presented with a message "check your email for a confirmation link" so you go do that. Where is context switching here?
Most of the users don't signup for something and then forget about it until they, by accident, stumble upon the email when they check their inbox the next time. Or am I wrong?
Also, I've never registered for a service and decided not to immediately check my email to activate my account when I'm prompted to. I can't recall a single time when I've come across a confirmation link while casually checking my email.
It's called double opt-in. It proves you're giving consent to be a member.
This can turn out bad though. I thought I had an apple-id when buying something on the apple site recently. But my standard passwords didn't work so I reset the password (via an email sent to me personal email address from the password reset sequence). When I logged in I found that my email address was actually registered to someone else, and I had their name, full address, phone number and credit card number but with the first 12 digits X'd out.
The person has a similar name to mine, and my email address is my initials and last name, so I believe they just made a typo in the email address when they signed up. But it seems pretty bad that you can do that without verification when doing so can give someone your personal information.
A motivated scammer could register a bunch of typoed email addresses and try resetting apple-id passwords. Then you have a 1 in 333 chance of buying stuff with their credit card because you have to guess the security code (I'm guessing you get 3 chances but you might get more).
Because it's really that hard to Ctrl+click a link in an email, archive it, and move on to the next email?
1. It's required by law in many places. That's why newsletter/auto-responder services use double opt-in.
2. If someone or something does sign-up on your behalf, why should you have to specifically opt out? So, it's always better to have someone confirm their e-mail, instead of having random users having to "opt out" of services they never signed up for.
3. Many a times, if it's some random site, the activation e-mail can go directly into your SPAM box. If an "opt out" type e-mail ends up in your SPAM box, then you probably won't see it, and it can potentially cause more damage.
4. For features like password reminder, it is always better, security-wise, to send the reset link to an e-mail you know for sure belongs to the account holder. If you mistyped your e-mail, and never received the conformation, you'd try creating an account again. However, if the account was activated by default, and you started using it right away, then you'd have all your e-mails going to someone else.
There might be more reasons...
I don't see how e-mail confirmation can be counted as "wasted seconds." It is to protect you. It's like taking a backup of your website. Many of them don't do it, because the few minutes it takes doesn't sound worthwhile. However, if the server crashes and your data is lost, only then you realize that those few minutes could have saved months of efforts.
Let's say that Shutterstock wanted to expand - they want to allow new users to download ANY two images they wanted for free.
Would you advise them to go with a confirmation-less email routine? If so, how do you prevent bots from creating bogus signups and then (a) stealing your images at will, (b) so that they can resell/rehost them in Russia/China and make money/compete with you, and (c) clogging up all of your bandwidth?
For example, the bot signs up with 00001@gmail.com then downloads 60MB files while another bot uses 0002@gmail.com then downloading 60MB in files, etc.
And please - no solutions that require manual intervention or cannot scale.
Now, you might detect that bulkdownloadrobot.biz is a bad domain and blacklist it, but all I have to do is to register a new domain each time that happens.
So now you implement a heuristic that detects patterns of signups from domains. Now, I start buying Gmail accounts created by workers in a CAPTCHA-solving sweatshop.
You've increased my costs slightly, but you haven't solved the problem.
The same tactic (along with 1x1px images etc) was already used by spammers to determine "alive" addresses, whose owners do read spam and do click on provided links.
That's the reason I'd be very annoyed if I'll get such email.
You have indeed. It is called "double opt-in" and legally required in many jurisdictions, before a web site can send you regular automated emails. Otherwise it might be considered Spam.
Personally with a fairly generic gmail address I see way too many random un-asked for messages with no opt-in confirmation.
And 10 lines of Perl? Lousy coder :P
Try it :) The email is used to set up your password, but you are able to use the app the first time without it! That way you will likely visit the app again when you check your email.