It’s bonkers to me that there’s any developers out there working for these companies that never thought to implement simple email verification.
It’s bonkers to me that there’s any developers out there working for these companies that never thought to implement simple email verification.
I have around 20 or 30 google accounts attached where i am the backup email address. Those people forget their passwords or stop using their accounts and i get email notifications about that. No confirmation from my side necessary.
I set up a new address that is less likely to end up with this problem. But migrating away from the old one is not easy…
I get so many other $MY_NAME emails, including bills (including multiple credit cards and things like Afterpay), deliveries, medical details/reports, family communications, etc, etc.
And it's very clear that quite a few online services blatantly don't verify email addresses, they just assume the email is valid and allow the person to start using it.
Does google not require a verification when you setup a backup email address?!
I have even had founder level emails that presumably are confidential sent to me because I share the name of someone operating in tech.
I respond or report when it's obviously some real person running a small group but for large monoliths there is very little to do except quickly reply to corporate email.
Really wish there was some kind of high level discussion about building something for this specific problem of non malicious wrong person same name errors.
Google could do it it's just not something that is monetizable at a scale they care about IMO and I have not been able to think of a way to make this work operating outside of email monoliths.
Would love to hear if anyone has ideas.
Other POV: I simply do not use email — like at all (don't even have a SPAM account anymore) — if your website requires me to enter an email address just to buy something, I WILL find a burner/temporary email that will allow the transaction script to proceed ("10 minute email").
I am personally grateful when a store allows me to proceed with a guest transaction [i.e. non-login, non-email purchase] — even if that means I might need to "call in" should the transaction be flagged/delayed [usually isn't].
Intentionally not giving examples to avoid hacker/targetting, but many US clothing manufacturers offer these frictionless (and legitimate) purchase pathways.
https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...
They are optimizing towards making it easy to purchase things on a whim.
They didn’t have a HIPAA coordinator by title, so I got to explain how to avoid this to their legal department.
Also, people usually type their emails correctly, especially these days with auto-fill. So not sending confirmation emails is optimizing for the happy path.
I was once even sent all of the legal proceedings for a court case by a lawyer who was sent to the wrong address.
Absolutely 100 percent fraud and security proof.
However as you it is an extra step and I imagine many retailers have done the math between fraud and friction...
I think it would be quite annoying to have to verify my purchase everywhere, just like how I don't wanna sign up to every single merchant online. Let me purchase as guest without having to enter OTPs.