Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I once had someone sign up for an electronic voicemail service with my email address. I was getting all their voicemail, including once about 50 in the space of an afternoon from a clearly distressed client of theirs. It took a very long email chain with customer service explaining that I couldn't log in to the account to change the email address because I didn't have the password and the account wasn't mine. A similar thing happened with a Playstation Network account.

Web developers: Please make sure to include a "Didn't sign up for this? Click here to disable/unsubscribe" option in sign up emails, rather than assuming that the person receiving the email is the correct person who knows the password.



To be fair, I have accidentally clicked on the "oh yeah, confirm this email address" when I suddenly realize "no, wait, I created that account with my other email address... what the heck is this?"

More of a problem with common big-name services like Facebook and Apple ID and whatnot.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: