259 karma · joined November 14, 2015
*In my original post I mistakenly wrote "millions"
Good timing?
That said, what's to stop a situation like that from arising as autonomous vehicles become more sophisticated?
Like others have said, the Android app is not worth installing unless you're okay with limited and, in some cases, poor functionality.
I suppose you can set it up with the Gmail or Outlook Android apps? I've never tried, as this defeats the purpose of not having those companies as your email provider :)
Still searching for a good Android mail app...
The difference is the web app runs within the browser sandbox while the CLI executes with user permissions.
As for the second point, I consider it a privacy breach if a service publicly associates my email address with their service without my consent. Sign-up forms do this when giving different responses when an email address is registered vs not registered.
As for how to handle it, if a user signs up with a new email address, you send them an email to verify their email address and instruct them to check their email. Similarly, if a user attempts to sign up with an already registered email address, you send them an email letting them know they already have an account and instruct them to check their email, which will provide them with a link to login.
In the latter case, if they enter the correct password, you can just directly tell the user they already have an account, as they've proven their identity.
1. Canonicalize email addresses
Whether or not dots or +asdf is considered okay, an email address used for identification needs to be canonicalized in order to avoid duplicate sign-ups.
2. Never leak information through sign-up forms
A login attempt either succeeds or fails. That is all the user should know. Telling the user if the attempted email address exists or does not exist is a privacy breach and a security breach as demonstrated in this article.
3. Never assume ownership of an email address until it is verified
Some services verify email addresses at some point in the user flow, some never verify, and few verify at the right point. The best sign-up flow I've seen is Slack where setting a password is part of the email verification flow and a user cannot set a password and own the account until they have verified the email address.
Thus, sending transactional emails beyond verify your email or reset your password before the email address has been verified opens one up to security breaches as in the case of Netflix.
But along those lines, I was considering sending emails using Gmail or Fastmail's servers. I'm unfamiliar with the potential pitfalls, if any, when going this route. I'm hoping someone can comment on that or share their experience.
It looks like a great deal if you already use EC2 because of the free 62k outgoing emails/month. But there doesn't seem to be a free tier otherwise.
This is something I've found fault with in Windows, and was greatly disappointed to see happen in Sierra.
I had been getting the High Sierra update reminder notification once a day for several days and normally just clicked "Remind me tomorrow" (since there's no option for "Don't remind me"). One day after having it pop up, I instead clicked "Try in an hour".
I expected this to ask me again in an hour, at which point I would choose whether or not to proceed with the update. Instead, while my MacBook was asleep with work open, it went ahead and updated the OS without my consent.
I don't (think) I lost any work, as I typically save things and Vim didn't leave any swp files. But the experience was disconcerting and bitterly reminiscent of Windows...
I also echo the sentiment that it's difficult finding a practical alternative.
[1] https://apple.stackexchange.com/questions/277967/major-issue...
It's important to understand that, by virtue of having been bestowed with a monopoly over the web, JavaScript holds a great deal of leverage as a language. If you want to develop for the web, you pretty much have to adopt JavaScript into your stack. It's no surprise, then, that Node became so popular. Being able to use that language you're forced to use for the client on the server and to run the same code has major benefits. The Node and npm developers got many things right to be sure. But Node and its ecosystem, by virtue of offering JavaScript, benefitted immensely from developers' desire to unify a previously disjoint part of their stack.
I find myself asking instead, how far will JavaScript's reach continue to stretch? Electron and React Native have become extremely popular. It's not just speculation, there is undeniable momentum.
Intergram achieves this (if I understand correctly) by using an intermediary server between the user and Telegram's API.
What I'm further asking is if the same behavior is possible without the intermediary server.
One of the good things I've read about Fastmail and Protonmail is they are incredibly reliable and privacy conscious. Likewise, they seem to focus primarily on email as opposed to Zoho which seems to offer a variety of services aimed at businesses. I wonder if the email service offered by Zoho for private email users holds up to that offered by Fastmail and Protonmail?