Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ages ago we intentionally configured MTA's to prevent enumeration and validation of email addresses on purpose. This appears to be a convoluted way to unwind that change and in my opinion would be heavily abused by shady email marketing groups on day 1. With all due respect I would never implement this in a company and would fight it. I choose my battles carefully before presenting them to the board until groups such as NCC [1] have reviewed the implementation concepts and details. All it would take is one poorly coded application using this incorrectly to be abused. i.e. devil in the implementation details or otherwise known as the weakest link. Having NCC validate every single implementation is going to get very expensive.

[1] - https://www.nccgroup.com/



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: